TechSpot

BSODs even after Alureon's gone?

By Auvic
Jul 22, 2012
  1. Hi again, sorry to be a bother:

    I recently ran into some issues with BSODs popping up every few minutes, and since the main advice for dealing with the Alureon virus/rootkit/something seems to be "reformat and hope for the best", I tried to salvage as much of my data as possible, then reformatted my c:\\ drive and reinstalled Win7. Even now, though, I'm having issues with using the computer; just while doing normal browsing, I'll have random BSODs, even though pretty much all the scans are coming out clean. Or so they seem, at least. Even after I cleared off the Alureon, one of my scans picked out a trojan, which doesn't make much sense, seeing as how I would expect the trojan to get cleared out during the reformat too.

    Not sure what to do right now to try and fix this, but here's the logs, just in case:

    Malwarebytes:
    Malwarebytes Anti-Malware (Trial) 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.07.22.08

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Vincent :: NOISEMACHINE [administrator]

    Protection: Enabled

    7/22/2012 1:01:55 PM
    mbam-log-2012-07-22 (13-01-55).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 184587
    Time elapsed: 1 minute(s), 25 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)

    Gmer:
    Gmer reported that it didn't find anything at all.




    Attach.log
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Ultimate
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/21/2012 12:57:45 PM
    System Uptime: 7/22/2012 12:55:49 PM (1 hours ago)
    .
    Motherboard: Gigabyte Technology Co., Ltd. | | EP45-UD3L
    Processor: Intel(R) Core(TM)2 Quad CPU Q9400 @ 2.66GHz | Socket 775 | 3600/450mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 931 GiB total, 882.998 GiB free.
    D: is FIXED (NTFS) - 699 GiB total, 390.655 GiB free.
    E: is FIXED (NTFS) - 0 GiB total, 0.059 GiB free.
    F: is FIXED (NTFS) - 931 GiB total, 189.526 GiB free.
    G: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP14: 7/21/2012 8:37:21 PM - Windows Update
    RP15: 7/21/2012 8:49:40 PM - Windows Update
    RP16: 7/21/2012 8:56:11 PM - Windows Update
    RP17: 7/21/2012 9:03:16 PM - Windows Update
    RP18: 7/21/2012 9:11:20 PM - Windows Update
    RP19: 7/21/2012 9:25:00 PM - Windows Update
    RP20: 7/21/2012 9:35:23 PM - Windows Update
    RP21: 7/21/2012 11:03:19 PM - Installed DirectX
    RP22: 7/22/2012 12:48:25 PM - PC Decrapifier Restore Point
    .
    ==== Installed Programs ======================
    .
    Adobe Flash Player 11 Plugin
    Catalyst Control Center
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    Google Chrome
    HDD Health v4.2
    League of Legends
    Malwarebytes Anti-Malware version 1.62.0.1300
    Mozilla Firefox 14.0.1 (x86 en-US)
    Mozilla Maintenance Service
    NETGEAR WG111v3 wireless USB 2.0 adapter
    Pando Media Booster
    Skype™ 5.10
    Steam
    .
    ==== Event Viewer Messages From Past Week ========
    .
    7/22/2012 4:31:00 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff880088b72b8, 0xfffff880088b6b20, 0xfffff880012aa884). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072212-793686-01.
    7/22/2012 4:04:27 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume Backup Backup.
    7/22/2012 4:02:40 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume D:.
    7/22/2012 3:23:32 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
    7/22/2012 2:24:08 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume \Device\HarddiskVolume3.
    7/22/2012 12:56:26 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the HDDHealth service to connect.
    7/22/2012 12:56:19 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff8800727e2f8, 0xfffff8800727db60, 0xfffff8800132c7a9). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072212-27877-01.
    7/21/2012 9:25:07 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 for x64-based Systems (KB2703157).
    7/21/2012 9:25:07 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Internet Explorer 8 Compatibility View List for Windows 7 for x64-based Systems (KB2598845).
    7/21/2012 9:24:10 PM, Error: Service Control Manager [7023] -
    7/21/2012 9:18:53 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070057: Update for Windows 7 for x64-based Systems (KB2387530).
    7/21/2012 9:05:22 PM, Error: Service Control Manager [7031] - The Microsoft .NET Framework NGEN v2.0.50727_X86 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:59:10 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070003: Security Update for Windows 7 for x64-based Systems (KB2718523).
    7/21/2012 8:44:50 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 5 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 6 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Themes service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Task Scheduler service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Shell Hardware Detection service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7034] - The Application Experience service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:44:26 PM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:44:22 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:44:22 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Shell Hardware Detection service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:44:22 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:44:22 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Application Experience service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:44:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Workstation service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:43:46 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the DNS Client service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:43:22 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:43:20 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:43:04 PM, Error: Service Control Manager [7034] - The Workstation service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:43:04 PM, Error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:43:04 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:42:50 PM, Error: Service Control Manager [7034] - The Windows Update service terminated unexpectedly. It has done this 2 time(s).
    7/21/2012 8:42:50 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:50 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 5 time(s).
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:22 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:42:14 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 4 time(s).
    7/21/2012 8:42:09 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:42:06 PM, Error: Service Control Manager [7034] - The Workstation service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:42:06 PM, Error: Service Control Manager [7034] - The Network Location Awareness service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:42:06 PM, Error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:42:06 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 3 time(s).
    7/21/2012 8:42:01 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 2 time(s).
    7/21/2012 8:42:01 PM, Error: Service Control Manager [7031] - The Workstation service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:42:01 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    7/21/2012 8:42:01 PM, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
    7/21/2012 8:41:46 PM, Error: Service Control Manager [7031] - The Workstation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:41:46 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    7/21/2012 8:41:46 PM, Error: Service Control Manager [7031] - The DNS Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 8:41:46 PM, Error: Service Control Manager [7031] - The Cryptographic Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 8:41:44 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    7/21/2012 8:41:38 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    7/21/2012 8:37:47 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 for x64-based Systems (KB2677070).
    7/21/2012 8:05:41 PM, Error: Service Control Manager [7031] - The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:31:47 PM, Error: Service Control Manager [7023] - The Windows Modules Installer service terminated with the following error: The process cannot access the file because it is being used by another process.
    7/21/2012 7:26:46 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Windows Internet Explorer 9 for Windows 7 for x64-based Systems.
    7/21/2012 7:21:12 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Program Compatibility Assistant Service service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Offline Files service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 7:20:12 PM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    7/21/2012 3:12:55 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000024 (0x00000000001904fb, 0xfffff88007bc2668, 0xfffff88007bc1ec0, 0xfffff880012add10). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072112-34164-01.
    7/21/2012 2:36:00 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
    7/21/2012 2:36:00 PM, Error: Service Control Manager [7000] - The Steam Client Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    7/21/2012 2:08:49 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Connections service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 11:05:31 PM, Error: Service Control Manager [7038] - The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    7/21/2012 11:05:31 PM, Error: Service Control Manager [7000] - The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.
    7/21/2012 11:05:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
    7/21/2012 1:51:03 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Microsoft Antimalware Service service, but this action failed with the following error: An instance of the service is already running.
    7/21/2012 1:50:48 PM, Error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
    7/21/2012 1:50:42 PM, Error: Microsoft Antimalware [5008] - Microsoft Antimalware engine has been terminated due to an unexpected error. Failure Type: Crash Exception code: 0xc0000005 Resource: file:C:\Windows\winsxs\Backup\wow64_microsoft-windows-smartcardsubsystem_31bf3856ad364e35_6.1.7600.16385_none_7e46db9db804b104_scarddlg.dll_b3dbecec
    7/21/2012 1:28:19 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002bc850a, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072112-18236-01.
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:19:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: Noisemachine\Vincent Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x8024001e Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x8024001e Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:17:59 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
    7/21/2012 1:06:35 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024d00f: Windows Update Setup Handler.
    .
    ==== End Of File ===========================
     
  2. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    DDS.log
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421
    Run by Vincent at 13:19:46 on 2012-07-22
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6142.3551 [GMT -5:00]
    .
    AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    c:\Program Files\Microsoft Security Client\MsMpEng.exe
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files (x86)\HDD Health\hddhealth.exe
    C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Windows\system32\sppsvc.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    mWinlogon: Userinit=userinit.exe,
    uRun: [Google Update] "C:\Users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
    mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HDDHEA~1.LNK - C:\Program Files (x86)\HDD Health\hddhealth.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{F0F8016D-0890-4031-B355-CC1A7C559357} : DhcpNameServer = 192.168.1.254
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
    mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\dbiou9hx.default\
    FF - prefs.js: browser.startup.homepage - gmail.com
    FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    FF - plugin: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-22 655944]
    R2 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
    R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
    R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;C:\Windows\system32\DRIVERS\wg111v3.sys --> C:\Windows\system32\DRIVERS\wg111v3.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 HDDHealth;HDDHealth;C:\Program Files (x86)\HDD Health\HDDHealthService.exe [2012-7-22 72640]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-22 250056]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-21 113120]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
    S3 SophosVirusRemovalTool;Sophos Virus Removal Tool;C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe --> C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2012-07-22 18:19:24 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{32EFCE45-5C52-4AC8-8974-4399B2874934}\mpengine.dll
    2012-07-22 08:40:25 -------- d-----r- C:\Program Files (x86)\Skype
    2012-07-22 08:37:00 -------- d-----w- C:\Program Files (x86)\HDD Health
    2012-07-22 08:33:15 -------- d-----w- C:\Users\Vincent\AppData\Local\Macromedia
    2012-07-22 08:29:00 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-22 08:29:00 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-07-22 05:17:56 -------- d-----w- C:\Users\Vincent\AppData\Roaming\Malwarebytes
    2012-07-22 05:17:47 -------- d-----w- C:\ProgramData\Malwarebytes
    2012-07-22 05:17:46 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-07-22 05:17:46 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-07-22 04:03:59 4910088 ----a-w- C:\Windows\System32\D3DX9_37.dll
    2012-07-22 03:59:29 -------- d--h--w- C:\Windows\msdownld.tmp
    2012-07-22 03:59:23 -------- d-----w- C:\Windows\SysWow64\directx
    2012-07-22 02:39:34 -------- d-----w- C:\Users\Vincent\AppData\Roaming\LolClient
    2012-07-22 02:39:02 -------- d-----w- C:\Program Files (x86)\AMD APP
    2012-07-22 02:35:41 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
    2012-07-22 02:35:40 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
    2012-07-22 02:35:21 1135104 ----a-w- C:\Windows\System32\FntCache.dll
    2012-07-22 02:32:24 -------- d-----w- C:\Users\Vincent\AppData\Local\ATI
    2012-07-22 02:32:24 -------- d-----w- C:\ProgramData\AMD
    2012-07-22 02:32:23 -------- d-----w- C:\Program Files (x86)\AMD AVT
    2012-07-22 02:32:19 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
    2012-07-22 02:32:19 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
    2012-07-22 02:32:05 -------- d-----w- C:\Program Files (x86)\ATI Technologies
    2012-07-22 02:29:57 6605824 ----a-w- C:\Windows\System32\atiumd64.dll
    2012-07-22 02:29:44 539136 ----a-w- C:\Windows\System32\atiadlxx.dll
    2012-07-22 02:28:51 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
    2012-07-22 02:28:23 4246528 ----a-w- C:\Windows\System32\atiumd6a.dll
    2012-07-22 02:27:43 45056 ----a-w- C:\Windows\System32\atiu9p64.dll
    2012-07-22 02:26:50 1831424 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
    2012-07-22 02:26:43 1120768 ----a-w- C:\Windows\System32\atiumd6v.dll
    2012-07-22 01:58:27 3147264 ----a-w- C:\Windows\System32\win32k.sys
    2012-07-22 01:58:05 311808 ----a-w- C:\Windows\System32\msv1_0.dll
    2012-07-22 01:58:05 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
    2012-07-22 01:48:41 -------- d-----w- C:\Users\Vincent\AppData\Local\Diagnostics
    2012-07-22 01:37:46 5504880 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-07-22 01:37:46 3958128 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-07-22 01:37:45 3902320 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-07-22 00:32:31 -------- d-----w- C:\Windows\SysWow64\Wat
    2012-07-22 00:32:31 -------- d-----w- C:\Windows\System32\Wat
    2012-07-22 00:17:04 720896 ----a-w- C:\Windows\System32\odbc32.dll
    2012-07-22 00:17:04 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
    2012-07-22 00:17:04 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
    2012-07-22 00:17:04 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17:03 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
    2012-07-22 00:17:03 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17:03 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
    2012-07-22 00:17:03 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
    2012-07-21 21:16:54 68616 ----a-w- C:\Windows\SysWow64\XAPOFX1_1.dll
    2012-07-21 21:16:54 509448 ----a-w- C:\Windows\SysWow64\XAudio2_2.dll
    2012-07-21 21:16:54 467984 ----a-w- C:\Windows\SysWow64\d3dx10_39.dll
    2012-07-21 21:16:54 3851784 ----a-w- C:\Windows\SysWow64\D3DX9_39.dll
    2012-07-21 21:16:54 1493528 ----a-w- C:\Windows\SysWow64\D3DCompiler_39.dll
    2012-07-21 21:13:17 -------- d-----w- C:\Riot Games
    2012-07-21 20:54:29 80896 ----a-w- C:\Windows\System32\imagehlp.dll
    2012-07-21 20:54:29 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
    2012-07-21 20:54:29 5120 ----a-w- C:\Windows\System32\wmi.dll
    2012-07-21 20:54:29 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
    2012-07-21 20:54:29 220672 ----a-w- C:\Windows\System32\wintrust.dll
    2012-07-21 20:54:29 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
    2012-07-21 20:54:29 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll
    2012-07-21 20:52:42 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
    2012-07-21 20:51:20 -------- d-----w- C:\Windows\Panther
    2012-07-21 20:17:54 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-07-21 20:16:59 264192 ----a-w- C:\Windows\System32\upnp.dll
    2012-07-21 20:09:56 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2012-07-21 20:08:58 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
    2012-07-21 20:07:55 640896 ----a-w- C:\Windows\System32\winload.efi
    2012-07-21 20:06:51 1895280 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2012-07-21 20:06:47 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06:47 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
    2012-07-21 20:06:47 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
    2012-07-21 20:06:47 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
    2012-07-21 20:06:47 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06:43 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
    2012-07-21 20:06:42 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
    2012-07-21 20:06:33 1739160 ----a-w- C:\Windows\System32\ntdll.dll
    2012-07-21 20:06:33 1292592 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-07-21 20:06:31 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
    2012-07-21 20:06:31 236032 ----a-w- C:\Windows\System32\srvsvc.dll
    2012-07-21 20:00:53 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-07-21 20:00:53 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-07-21 19:33:51 -------- d-----w- C:\Users\Vincent\AppData\Local\PMB Files
    2012-07-21 19:33:50 -------- d-----w- C:\ProgramData\PMB Files
    2012-07-21 19:33:29 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
    2012-07-21 19:33:28 -------- d-----w- C:\Program Files (x86)\Steam
    2012-07-21 19:33:09 -------- d-----w- C:\Program Files (x86)\Pando Networks
    2012-07-21 18:48:56 -------- d-----w- C:\ProgramData\Sophos
    2012-07-21 18:43:22 0 ----a-w- C:\Windows\ativpsrm.bin
    2012-07-21 18:41:23 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-07-21 18:33:58 139264 ----a-w- C:\Windows\System32\cabview.dll
    2012-07-21 18:33:58 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
    2012-07-21 18:33:57 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-07-21 18:33:57 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-07-21 18:33:56 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-07-21 18:25:12 -------- d-----w- C:\Users\Vincent\AppData\Local\Mozilla
    2012-07-21 18:25:05 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
    2012-07-21 18:21:30 -------- d-----w- C:\Program Files\ATI Technologies
    2012-07-21 18:21:29 -------- d-----w- C:\Program Files\ATI
    2012-07-21 18:21:00 -------- d-----w- C:\AMD
    2012-07-21 18:20:20 927800 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9A70AE52-D427-4C6E-A954-A32D38311C2F}\gapaengine.dll
    2012-07-21 18:20:16 279656 ------w- C:\Windows\System32\MpSigStub.exe
    2012-07-21 18:15:50 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2012-07-21 18:15:48 -------- d-----w- C:\Program Files\Microsoft Security Client
    2012-07-21 18:15:38 374664 ----a-w- C:\Windows\System32\drivers\netio.sys
    2012-07-21 18:07:15 -------- d-----w- C:\Users\Vincent\AppData\Local\Google
    2012-07-21 18:03:16 -------- d-----w- C:\Users\Vincent\AppData\Local\Deployment
    2012-07-21 18:03:16 -------- d-----w- C:\Users\Vincent\AppData\Local\Apps
    2012-07-21 18:03:00 2622464 ----a-w- C:\Windows\System32\wucltux.dll
    2012-07-21 18:02:58 99840 ----a-w- C:\Windows\System32\wudriver.dll
    2012-07-21 18:02:36 36864 ----a-w- C:\Windows\System32\wuapp.exe
    2012-07-21 18:02:36 186752 ----a-w- C:\Windows\System32\wuwebv.dll
    2012-07-21 18:01:31 -------- d-----w- C:\OEMSettings
    2012-07-21 18:01:12 446976 ----a-w- C:\Windows\System32\drivers\wg111v3.sys
    2012-07-21 18:01:11 -------- d-----w- C:\Program Files (x86)\NETGEAR
    2012-07-21 18:00:19 -------- d-----w- C:\Users\Vincent\AppData\Local\ElevatedDiagnostics
    2012-07-21 17:58:52 -------- d-sh--w- C:\Windows\Installer
    2012-07-21 17:58:52 -------- d-----w- C:\Windows\Downloaded Installations
    2012-07-04 07:30:12 54784 ----a-w- C:\Windows\System32\OpenCL.dll
    2012-07-04 07:30:08 50176 ----a-w- C:\Windows\SysWow64\OpenCL.dll
    .
    ==================== Find3M ====================
    .
    2012-07-22 02:12:59 91648 ----a-w- C:\Windows\System32\SetIEInstalledDate.exe
    2012-07-22 02:12:59 85504 ----a-w- C:\Windows\System32\iesetup.dll
    2012-07-22 02:12:59 76800 ----a-w- C:\Windows\System32\tdc.ocx
    2012-07-22 02:12:59 603648 ----a-w- C:\Windows\System32\vbscript.dll
    2012-07-22 02:12:59 48640 ----a-w- C:\Windows\System32\mshtmler.dll
    2012-07-22 02:12:59 448512 ----a-w- C:\Windows\System32\html.iec
    2012-07-22 02:12:59 30720 ----a-w- C:\Windows\System32\licmgr10.dll
    2012-07-22 02:12:59 165888 ----a-w- C:\Windows\System32\iexpress.exe
    2012-07-22 02:12:59 160256 ----a-w- C:\Windows\System32\wextract.exe
    2012-07-22 02:12:59 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-07-22 02:12:59 135168 ----a-w- C:\Windows\System32\IEAdvpack.dll
    2012-07-22 02:12:59 111616 ----a-w- C:\Windows\System32\iesysprep.dll
    2012-06-11 18:59:38 10248192 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
    2012-06-11 18:50:46 187392 ----a-w- C:\Windows\System32\clinfo.exe
    2012-06-11 18:50:30 75264 ----a-w- C:\Windows\System32\OpenVideo64.dll
    2012-06-11 18:50:24 65024 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
    2012-06-11 18:50:18 63488 ----a-w- C:\Windows\System32\OVDecode64.dll
    2012-06-11 18:50:14 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
    2012-06-11 18:50:06 16457728 ----a-w- C:\Windows\System32\amdocl64.dll
    2012-06-11 18:49:22 13008896 ----a-w- C:\Windows\SysWow64\amdocl.dll
    2012-06-11 18:35:48 70144 ----a-w- C:\Windows\System32\coinst_8.98.dll
    2012-06-11 18:29:34 24826368 ----a-w- C:\Windows\System32\atio6axx.dll
    2012-06-11 18:00:32 20467712 ----a-w- C:\Windows\SysWow64\atioglxx.dll
    2012-06-11 17:25:06 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
    2012-06-11 17:24:58 924160 ----a-w- C:\Windows\SysWow64\aticfx32.dll
    2012-06-11 17:23:12 1090560 ----a-w- C:\Windows\System32\aticfx64.dll
    2012-06-11 17:19:58 532992 ----a-w- C:\Windows\System32\atieclxx.exe
    2012-06-11 17:19:14 239616 ----a-w- C:\Windows\System32\atiesrxx.exe
    2012-06-11 17:17:56 120320 ----a-w- C:\Windows\System32\atitmm64.dll
    2012-06-11 17:17:42 21504 ----a-w- C:\Windows\System32\atimuixx.dll
    2012-06-11 17:17:38 59392 ----a-w- C:\Windows\System32\atiedu64.dll
    2012-06-11 17:17:32 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
    2012-06-11 17:16:48 6301696 ----a-w- C:\Windows\SysWow64\atidxx32.dll
    2012-06-11 17:01:56 6914560 ----a-w- C:\Windows\System32\atidxx64.dll
    2012-06-11 16:45:48 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
    2012-06-11 16:45:46 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
    2012-06-11 16:45:44 5480448 ----a-w- C:\Windows\SysWow64\atiumdag.dll
    2012-06-11 16:45:40 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
    2012-06-11 16:45:38 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
    2012-06-11 16:45:26 15703040 ----a-w- C:\Windows\System32\aticaldd64.dll
    2012-06-11 16:43:18 4729344 ----a-w- C:\Windows\SysWow64\atiumdva.dll
    2012-06-11 16:40:58 13277696 ----a-w- C:\Windows\SysWow64\aticaldd.dll
    2012-06-11 16:26:52 368640 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
    2012-06-11 16:26:40 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
    2012-06-11 16:26:36 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
    2012-06-11 16:26:36 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
    2012-06-11 16:26:30 41984 ----a-w- C:\Windows\System32\atig6txx.dll
    2012-06-11 16:26:22 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll
    2012-06-11 16:26:14 367616 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
    2012-06-11 16:25:20 54784 ----a-w- C:\Windows\System32\atiuxp64.dll
    2012-06-11 16:25:12 42496 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
    2012-06-11 16:24:58 32768 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
    2012-06-11 16:24:24 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
    2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\atimpc64.dll
    2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\amdpcom64.dll
    2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll
    2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
    2012-06-06 05:50:50 2003968 ----a-w- C:\Windows\System32\msxml6.dll
    2012-06-06 05:50:50 1880064 ----a-w- C:\Windows\System32\msxml3.dll
    2012-06-06 05:09:46 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
    2012-06-06 05:09:46 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
    2012-06-02 05:38:26 95088 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
    2012-06-02 05:38:24 152432 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2012-06-02 05:37:45 459216 ----a-w- C:\Windows\System32\drivers\cng.sys
    2012-06-02 05:27:02 340992 ----a-w- C:\Windows\System32\schannel.dll
    2012-06-02 05:27:00 307200 ----a-w- C:\Windows\System32\ncrypt.dll
    2012-06-02 04:48:39 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
    2012-06-02 04:48:35 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
    2012-06-02 04:47:31 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
    2012-06-02 04:42:51 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    2012-05-02 05:32:43 208896 ----a-w- C:\Windows\System32\profsvc.dll
    2012-04-28 03:50:40 204800 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-04-26 05:34:38 76288 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-04-26 05:34:37 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-04-24 05:59:45 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
    2012-04-24 05:59:45 1460224 ----a-w- C:\Windows\System32\crypt32.dll
    2012-04-24 05:59:45 140288 ----a-w- C:\Windows\System32\cryptnet.dll
    2012-04-24 04:47:04 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2012-04-24 04:47:04 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    2012-04-24 04:47:03 1156608 ----a-w- C:\Windows\SysWow64\crypt32.dll
    .
    ============= FINISH: 13:20:35.19 ===============
     
  3. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    =====================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  4. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    RK:
    RogueKiller V7.6.4 [07/17/2012] by Tigzy

    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7600 ) 64 bits version
    Started in : Normal mode
    User: Vincent [Admin rights]
    Mode: Scan -- Date: 07/22/2012 14:18:11

    ¤¤¤ Bad processes: 0 ¤¤¤

    ¤¤¤ Registry Entries: 2 ¤¤¤
    [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver: [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: WDC WD1001FALS-00J7B0 ATA Device +++++
    --- User ---
    [MBR] 97eb5ad0d454d7926d6bcb63f3b827b1
    [BSP] c965afaab793a8107a3ed1784c627274 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: ST3750330AS ATA Device +++++
    --- User ---
    [MBR] 852df5e9ec286f88eaeb41c1a832395c
    [BSP] 1afcd3a018c8d11193bf55da28778d02 : Windows 7 MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 715402 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive2: ST31000528AS ATA Device +++++
    --- User ---
    [MBR] f05533e990d0436e93ee238a0f5ee6d4
    [BSP] 5eb0dd7e0296bddf0cb2cf66da5b79c9 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive3: FLASH Drive 3S_USB20 USB Device +++++
    --- User ---
    [MBR] 10b37fe58f5d2618e64c219f8d8d0feb
    [BSP] 9f4bbb776cd71dbf0ad11bb573a7adc6 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 7635 Mo
    User = LL1 ... OK!
    Error reading LL2 MBR!

    Finished : << RKreport[1].txt >>
    RKreport[1].txt


    Here's the RK log; aswMBR crashed the first time I ran it, running it again.
     
  5. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    Tried to run aswMBR again, it crashed.
    Tried to run aswMBR in safe mode, crashed as well.
    Re-tried aswMBR in safe mode + admin privileges: "The instruction at 0/773ae423 referenced memory at 0x00000000. The memory could not be written." and then crash, but at least I got a message out of it.

    .....I don't think my hardware is broken, but this is a weird bug, if nothing else.
     
  6. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  7. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    Tried to run TDSSKiller off the desktop, didn't work. Ditto attempting to run with admin privileges.

    Loaded TDSSKiller onto a usb stick, and ran it from there. Initially didn't report anything; changed parameters and checked both bottom boxes, and got this:

    15:01:18.0313 0856 TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
    15:01:18.0734 0856 ============================================================
    15:01:18.0734 0856 Current date / time: 2012/07/22 15:01:18.0734
    15:01:18.0734 0856 SystemInfo:
    15:01:18.0734 0856
    15:01:18.0734 0856 OS Version: 6.1.7600 ServicePack: 0.0
    15:01:18.0734 0856 Product type: Workstation
    15:01:18.0734 0856 ComputerName: NOISEMACHINE
    15:01:18.0734 0856 UserName: Vincent
    15:01:18.0734 0856 Windows directory: C:\Windows
    15:01:18.0734 0856 System windows directory: C:\Windows
    15:01:18.0734 0856 Running under WOW64
    15:01:18.0734 0856 Processor architecture: Intel x64
    15:01:18.0734 0856 Number of processors: 4
    15:01:18.0734 0856 Page size: 0x1000
    15:01:18.0734 0856 Boot type: Normal boot
    15:01:18.0734 0856 ============================================================
    15:01:20.0481 0856 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
    15:01:20.0497 0856 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    15:01:20.0512 0856 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
    15:01:20.0512 0856 Drive \Device\Harddisk3\DR3 - Size: 0x1DD31E000 (7.46 Gb), SectorSize: 0x200, Cylinders: 0x3CD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    15:01:20.0512 0856 ============================================================
    15:01:20.0512 0856 \Device\Harddisk0\DR0:
    15:01:20.0512 0856 MBR partitions:
    15:01:20.0512 0856 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    15:01:20.0512 0856 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
    15:01:20.0512 0856 \Device\Harddisk1\DR1:
    15:01:20.0512 0856 MBR partitions:
    15:01:20.0512 0856 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x57545000
    15:01:20.0512 0856 \Device\Harddisk2\DR2:
    15:01:20.0512 0856 MBR partitions:
    15:01:20.0512 0856 \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    15:01:20.0512 0856 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
    15:01:20.0512 0856 \Device\Harddisk3\DR3:
    15:01:20.0528 0856 MBR partitions:
    15:01:20.0528 0856 \Device\Harddisk3\DR3\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xEE98B1
    15:01:20.0528 0856 ============================================================
    15:01:20.0543 0856 C: <-> \Device\Harddisk0\DR0\Partition1
    15:01:20.0559 0856 D: <-> \Device\Harddisk1\DR1\Partition0
    15:01:20.0590 0856 E: <-> \Device\Harddisk2\DR2\Partition0
    15:01:20.0606 0856 F: <-> \Device\Harddisk2\DR2\Partition1
    15:01:20.0606 0856 ============================================================
    15:01:20.0606 0856 Initialize success
    15:01:20.0606 0856 ============================================================
    15:01:21.0635 1712 ============================================================
    15:01:21.0635 1712 Scan started
    15:01:21.0635 1712 Mode: Manual;
    15:01:21.0635 1712 ============================================================
    15:01:22.0306 1712 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
    15:01:22.0306 1712 1394ohci - ok
    15:01:22.0337 1712 54556415 - ok
    15:01:22.0353 1712 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
    15:01:22.0353 1712 ACPI - ok
    15:01:22.0369 1712 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
    15:01:22.0369 1712 AcpiPmi - ok
    15:01:22.0431 1712 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    15:01:22.0431 1712 AdobeFlashPlayerUpdateSvc - ok
    15:01:22.0462 1712 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    15:01:22.0462 1712 adp94xx - ok
    15:01:22.0493 1712 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    15:01:22.0493 1712 adpahci - ok
    15:01:22.0509 1712 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    15:01:22.0509 1712 adpu320 - ok
    15:01:22.0525 1712 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    15:01:22.0525 1712 AeLookupSvc - ok
    15:01:22.0571 1712 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
    15:01:22.0587 1712 AFD - ok
    15:01:22.0603 1712 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
    15:01:22.0603 1712 agp440 - ok
    15:01:22.0618 1712 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    15:01:22.0618 1712 ALG - ok
    15:01:22.0634 1712 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
    15:01:22.0634 1712 aliide - ok
    15:01:22.0665 1712 AMD External Events Utility (9c616ba191b80f5cd1a1b9553e107100) C:\Windows\system32\atiesrxx.exe
    15:01:22.0665 1712 AMD External Events Utility - ok
    15:01:22.0665 1712 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
    15:01:22.0665 1712 amdide - ok
    15:01:22.0665 1712 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    15:01:22.0665 1712 AmdK8 - ok
    15:01:23.0039 1712 amdkmdag (5165e83751b8ff40e5e4925996fcc506) C:\Windows\system32\DRIVERS\atikmdag.sys
    15:01:23.0133 1712 amdkmdag - ok
    15:01:23.0242 1712 amdkmdap (86ab3cf484260c4318f3a6e8b035f422) C:\Windows\system32\DRIVERS\atikmpag.sys
    15:01:23.0242 1712 amdkmdap - ok
    15:01:23.0242 1712 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    15:01:23.0242 1712 AmdPPM - ok
    15:01:23.0258 1712 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
    15:01:23.0258 1712 amdsata - ok
    15:01:23.0273 1712 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    15:01:23.0273 1712 amdsbs - ok
    15:01:23.0289 1712 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
    15:01:23.0289 1712 amdxata - ok
    15:01:23.0305 1712 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
    15:01:23.0305 1712 AppID - ok
    15:01:23.0320 1712 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    15:01:23.0336 1712 AppIDSvc - ok
    15:01:23.0351 1712 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
    15:01:23.0351 1712 Appinfo - ok
    15:01:23.0367 1712 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
    15:01:23.0367 1712 AppMgmt - ok
    15:01:23.0383 1712 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    15:01:23.0383 1712 arc - ok
    15:01:23.0383 1712 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    15:01:23.0383 1712 arcsas - ok
    15:01:23.0398 1712 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    15:01:23.0398 1712 AsyncMac - ok
    15:01:23.0414 1712 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
    15:01:23.0414 1712 atapi - ok
    15:01:23.0429 1712 AtiHDAudioService (24464b908e143d2561e9e452fee97309) C:\Windows\system32\drivers\AtihdW76.sys
    15:01:23.0429 1712 AtiHDAudioService - ok
    15:01:23.0476 1712 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    15:01:23.0476 1712 AudioEndpointBuilder - ok
    15:01:23.0492 1712 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    15:01:23.0492 1712 AudioSrv - ok
    15:01:23.0492 1712 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
    15:01:23.0507 1712 AxInstSV - ok
    15:01:23.0523 1712 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    15:01:23.0539 1712 b06bdrv - ok
    15:01:23.0554 1712 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    15:01:23.0570 1712 b57nd60a - ok
    15:01:23.0570 1712 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    15:01:23.0570 1712 BDESVC - ok
    15:01:23.0585 1712 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    15:01:23.0585 1712 Beep - ok
    15:01:23.0632 1712 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
    15:01:23.0632 1712 BFE - ok
    15:01:23.0679 1712 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
    15:01:23.0695 1712 BITS - ok
    15:01:23.0726 1712 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    15:01:23.0726 1712 blbdrive - ok
    15:01:23.0741 1712 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
    15:01:23.0741 1712 bowser - ok
    15:01:23.0741 1712 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    15:01:23.0741 1712 BrFiltLo - ok
    15:01:23.0741 1712 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    15:01:23.0741 1712 BrFiltUp - ok
    15:01:23.0757 1712 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
    15:01:23.0757 1712 Browser - ok
    15:01:23.0773 1712 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    15:01:23.0773 1712 Brserid - ok
    15:01:23.0773 1712 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    15:01:23.0788 1712 BrSerWdm - ok
    15:01:23.0788 1712 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    15:01:23.0788 1712 BrUsbMdm - ok
    15:01:23.0788 1712 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    15:01:23.0788 1712 BrUsbSer - ok
    15:01:23.0788 1712 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    15:01:23.0788 1712 BTHMODEM - ok
    15:01:23.0804 1712 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    15:01:23.0804 1712 bthserv - ok
    15:01:23.0819 1712 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    15:01:23.0819 1712 cdfs - ok
    15:01:23.0835 1712 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
    15:01:23.0835 1712 cdrom - ok
    15:01:23.0851 1712 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    15:01:23.0851 1712 CertPropSvc - ok
    15:01:23.0851 1712 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    15:01:23.0851 1712 circlass - ok
    15:01:23.0866 1712 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    15:01:23.0866 1712 CLFS - ok
    15:01:23.0897 1712 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    15:01:23.0897 1712 clr_optimization_v2.0.50727_32 - ok
    15:01:23.0929 1712 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    15:01:23.0929 1712 clr_optimization_v2.0.50727_64 - ok
    15:01:23.0975 1712 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    15:01:23.0975 1712 clr_optimization_v4.0.30319_32 - ok
    15:01:23.0991 1712 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    15:01:23.0991 1712 clr_optimization_v4.0.30319_64 - ok
    15:01:24.0007 1712 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    15:01:24.0007 1712 CmBatt - ok
    15:01:24.0007 1712 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
    15:01:24.0022 1712 cmdide - ok
    15:01:24.0038 1712 CNG (ca7720b73446fddec5c69519c1174c98) C:\Windows\system32\Drivers\cng.sys
    15:01:24.0053 1712 CNG - ok
    15:01:24.0053 1712 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    15:01:24.0053 1712 Compbatt - ok
    15:01:24.0069 1712 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
    15:01:24.0069 1712 CompositeBus - ok
    15:01:24.0085 1712 COMSysApp - ok
    15:01:24.0085 1712 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    15:01:24.0100 1712 crcdisk - ok
    15:01:24.0116 1712 CryptSvc (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
    15:01:24.0116 1712 CryptSvc - ok
    15:01:24.0163 1712 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
    15:01:24.0163 1712 CSC - ok
    15:01:24.0194 1712 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
    15:01:24.0194 1712 CscService - ok
    15:01:24.0241 1712 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    15:01:24.0241 1712 DcomLaunch - ok
    15:01:24.0272 1712 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    15:01:24.0287 1712 defragsvc - ok
    15:01:24.0319 1712 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
    15:01:24.0319 1712 DfsC - ok
    15:01:24.0350 1712 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
    15:01:24.0350 1712 Dhcp - ok
    15:01:24.0350 1712 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    15:01:24.0350 1712 discache - ok
    15:01:24.0365 1712 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    15:01:24.0365 1712 Disk - ok
    15:01:24.0381 1712 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
    15:01:24.0381 1712 Dnscache - ok
    15:01:24.0412 1712 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
    15:01:24.0412 1712 dot3svc - ok
    15:01:24.0428 1712 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
    15:01:24.0428 1712 DPS - ok
    15:01:24.0459 1712 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    15:01:24.0459 1712 drmkaud - ok
    15:01:24.0506 1712 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
    15:01:24.0506 1712 DXGKrnl - ok
    15:01:24.0521 1712 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    15:01:24.0521 1712 EapHost - ok
    15:01:24.0662 1712 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    15:01:24.0709 1712 ebdrv - ok
    15:01:24.0771 1712 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
    15:01:24.0771 1712 EFS - ok
    15:01:24.0818 1712 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
    15:01:24.0833 1712 ehRecvr - ok
    15:01:24.0849 1712 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    15:01:24.0849 1712 ehSched - ok
    15:01:24.0880 1712 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    15:01:24.0880 1712 elxstor - ok
    15:01:24.0896 1712 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
    15:01:24.0896 1712 ErrDev - ok
    15:01:24.0927 1712 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    15:01:24.0927 1712 EventSystem - ok
    15:01:24.0943 1712 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    15:01:24.0943 1712 exfat - ok
    15:01:24.0958 1712 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    15:01:24.0958 1712 fastfat - ok
    15:01:24.0989 1712 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
    15:01:25.0005 1712 Fax - ok
    15:01:25.0021 1712 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    15:01:25.0021 1712 fdc - ok
    15:01:25.0036 1712 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    15:01:25.0036 1712 fdPHost - ok
    15:01:25.0052 1712 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    15:01:25.0052 1712 FDResPub - ok
    15:01:25.0052 1712 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    15:01:25.0052 1712 FileInfo - ok
    15:01:25.0067 1712 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    15:01:25.0067 1712 Filetrace - ok
    15:01:25.0067 1712 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    15:01:25.0067 1712 flpydisk - ok
    15:01:25.0083 1712 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
    15:01:25.0083 1712 FltMgr - ok
    15:01:25.0145 1712 FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
    15:01:25.0161 1712 FontCache - ok
    15:01:25.0208 1712 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    15:01:25.0208 1712 FontCache3.0.0.0 - ok
    15:01:25.0208 1712 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    15:01:25.0208 1712 FsDepends - ok
    15:01:25.0223 1712 Fs_Rec (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
    15:01:25.0223 1712 Fs_Rec - ok
    15:01:25.0255 1712 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
    15:01:25.0255 1712 fvevol - ok
    15:01:25.0270 1712 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    15:01:25.0286 1712 gagp30kx - ok
    15:01:25.0317 1712 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
    15:01:25.0333 1712 gpsvc - ok
    15:01:25.0333 1712 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    15:01:25.0333 1712 hcw85cir - ok
    15:01:25.0364 1712 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
    15:01:25.0364 1712 HdAudAddService - ok
    15:01:25.0379 1712 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    15:01:25.0379 1712 HDAudBus - ok
    15:01:25.0442 1712 HDDHealth (354f7ac7ae454a1daf85bf7c0ffefd07) C:\Program Files (x86)\HDD Health\HDDHealthService.exe
    15:01:25.0442 1712 HDDHealth - ok
    15:01:25.0457 1712 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    15:01:25.0457 1712 HidBatt - ok
    15:01:25.0473 1712 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    15:01:25.0473 1712 HidBth - ok
    15:01:25.0473 1712 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    15:01:25.0473 1712 HidIr - ok
    15:01:25.0489 1712 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
    15:01:25.0489 1712 hidserv - ok
    15:01:25.0489 1712 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
    15:01:25.0489 1712 HidUsb - ok
    15:01:25.0504 1712 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
    15:01:25.0504 1712 hkmsvc - ok
    15:01:25.0535 1712 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
    15:01:25.0535 1712 HomeGroupListener - ok
    15:01:25.0551 1712 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
    15:01:25.0551 1712 HomeGroupProvider - ok
    15:01:25.0567 1712 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
    15:01:25.0567 1712 HpSAMD - ok
    15:01:25.0613 1712 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
    15:01:25.0613 1712 HTTP - ok
    15:01:25.0613 1712 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
    15:01:25.0613 1712 hwpolicy - ok
    15:01:25.0629 1712 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    15:01:25.0629 1712 i8042prt - ok
    15:01:25.0645 1712 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
    15:01:25.0645 1712 iaStorV - ok
    15:01:25.0707 1712 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    15:01:25.0723 1712 idsvc - ok
    15:01:25.0723 1712 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    15:01:25.0723 1712 iirsp - ok
    15:01:25.0769 1712 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
    15:01:25.0785 1712 IKEEXT - ok
    15:01:25.0801 1712 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
    15:01:25.0801 1712 intelide - ok
    15:01:25.0816 1712 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    15:01:25.0816 1712 intelppm - ok
    15:01:25.0832 1712 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    15:01:25.0832 1712 IPBusEnum - ok
    15:01:25.0847 1712 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    15:01:25.0847 1712 IpFilterDriver - ok
    15:01:25.0879 1712 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
    15:01:25.0879 1712 iphlpsvc - ok
    15:01:25.0894 1712 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
    15:01:25.0894 1712 IPMIDRV - ok
    15:01:25.0894 1712 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    15:01:25.0894 1712 IPNAT - ok
    15:01:25.0910 1712 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    15:01:25.0910 1712 IRENUM - ok
    15:01:25.0910 1712 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
    15:01:25.0910 1712 isapnp - ok
    15:01:25.0925 1712 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
    15:01:25.0925 1712 iScsiPrt - ok
    15:01:25.0925 1712 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    15:01:25.0925 1712 kbdclass - ok
    15:01:25.0925 1712 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
    15:01:25.0925 1712 kbdhid - ok
    15:01:25.0957 1712 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:25.0957 1712 KeyIso - ok
     
  8. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    15:01:25.0957 1712 KSecDD (4f4b5fde429416877de7143044582eb5) C:\Windows\system32\Drivers\ksecdd.sys
    15:01:25.0957 1712 KSecDD - ok
    15:01:25.0972 1712 KSecPkg (6f40465a44ecdc1731befafec5bdd03c) C:\Windows\system32\Drivers\ksecpkg.sys
    15:01:25.0972 1712 KSecPkg - ok
    15:01:25.0972 1712 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    15:01:25.0972 1712 ksthunk - ok
    15:01:26.0003 1712 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    15:01:26.0003 1712 KtmRm - ok
    15:01:26.0019 1712 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
    15:01:26.0019 1712 LanmanServer - ok
    15:01:26.0035 1712 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
    15:01:26.0050 1712 LanmanWorkstation - ok
    15:01:26.0066 1712 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    15:01:26.0066 1712 lltdio - ok
    15:01:26.0097 1712 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    15:01:26.0097 1712 lltdsvc - ok
    15:01:26.0113 1712 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    15:01:26.0113 1712 lmhosts - ok
    15:01:26.0128 1712 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    15:01:26.0128 1712 LSI_FC - ok
    15:01:26.0144 1712 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    15:01:26.0144 1712 LSI_SAS - ok
    15:01:26.0144 1712 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    15:01:26.0144 1712 LSI_SAS2 - ok
    15:01:26.0159 1712 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    15:01:26.0159 1712 LSI_SCSI - ok
    15:01:26.0159 1712 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    15:01:26.0159 1712 luafv - ok
    15:01:26.0206 1712 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
    15:01:26.0206 1712 MBAMProtector - ok
    15:01:26.0269 1712 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    15:01:26.0284 1712 MBAMService - ok
    15:01:26.0284 1712 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
    15:01:26.0284 1712 Mcx2Svc - ok
    15:01:26.0300 1712 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    15:01:26.0300 1712 megasas - ok
    15:01:26.0300 1712 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    15:01:26.0315 1712 MegaSR - ok
    15:01:26.0331 1712 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    15:01:26.0331 1712 MMCSS - ok
    15:01:26.0347 1712 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    15:01:26.0347 1712 Modem - ok
    15:01:26.0347 1712 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    15:01:26.0347 1712 monitor - ok
    15:01:26.0362 1712 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    15:01:26.0362 1712 mouclass - ok
    15:01:26.0362 1712 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    15:01:26.0362 1712 mouhid - ok
    15:01:26.0378 1712 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
    15:01:26.0378 1712 mountmgr - ok
    15:01:26.0409 1712 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    15:01:26.0425 1712 MozillaMaintenance - ok
    15:01:26.0440 1712 MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
    15:01:26.0440 1712 MpFilter - ok
    15:01:26.0456 1712 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
    15:01:26.0456 1712 mpio - ok
    15:01:26.0456 1712 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    15:01:26.0456 1712 mpsdrv - ok
    15:01:26.0503 1712 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
    15:01:26.0518 1712 MpsSvc - ok
    15:01:26.0534 1712 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
    15:01:26.0534 1712 MRxDAV - ok
    15:01:26.0549 1712 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
    15:01:26.0565 1712 mrxsmb - ok
    15:01:26.0581 1712 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    15:01:26.0581 1712 mrxsmb10 - ok
    15:01:26.0581 1712 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    15:01:26.0596 1712 mrxsmb20 - ok
    15:01:26.0596 1712 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
    15:01:26.0596 1712 msahci - ok
    15:01:26.0596 1712 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
    15:01:26.0596 1712 msdsm - ok
    15:01:26.0612 1712 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    15:01:26.0612 1712 MSDTC - ok
    15:01:26.0627 1712 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    15:01:26.0627 1712 Msfs - ok
    15:01:26.0627 1712 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    15:01:26.0627 1712 mshidkmdf - ok
    15:01:26.0643 1712 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
    15:01:26.0643 1712 msisadrv - ok
    15:01:26.0674 1712 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    15:01:26.0690 1712 MSiSCSI - ok
    15:01:26.0690 1712 msiserver - ok
    15:01:26.0721 1712 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    15:01:26.0721 1712 MSKSSRV - ok
    15:01:26.0752 1712 MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
    15:01:26.0752 1712 MsMpSvc - ok
    15:01:26.0768 1712 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    15:01:26.0768 1712 MSPCLOCK - ok
    15:01:26.0768 1712 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    15:01:26.0768 1712 MSPQM - ok
    15:01:26.0783 1712 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
    15:01:26.0783 1712 MsRPC - ok
    15:01:26.0783 1712 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
    15:01:26.0783 1712 mssmbios - ok
    15:01:26.0783 1712 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    15:01:26.0783 1712 MSTEE - ok
    15:01:26.0815 1712 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    15:01:26.0815 1712 MTConfig - ok
    15:01:26.0830 1712 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    15:01:26.0830 1712 Mup - ok
    15:01:26.0846 1712 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
    15:01:26.0861 1712 napagent - ok
    15:01:26.0893 1712 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    15:01:26.0908 1712 NativeWifiP - ok
    15:01:26.0955 1712 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
    15:01:26.0955 1712 NDIS - ok
    15:01:26.0986 1712 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    15:01:27.0002 1712 NdisCap - ok
    15:01:27.0002 1712 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    15:01:27.0017 1712 NdisTapi - ok
    15:01:27.0017 1712 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
    15:01:27.0017 1712 Ndisuio - ok
    15:01:27.0033 1712 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
    15:01:27.0033 1712 NdisWan - ok
    15:01:27.0033 1712 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
    15:01:27.0033 1712 NDProxy - ok
    15:01:27.0033 1712 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    15:01:27.0033 1712 NetBIOS - ok
    15:01:27.0049 1712 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
    15:01:27.0049 1712 NetBT - ok
    15:01:27.0064 1712 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:27.0064 1712 Netlogon - ok
    15:01:27.0095 1712 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    15:01:27.0111 1712 Netman - ok
    15:01:27.0127 1712 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    15:01:27.0127 1712 netprofm - ok
    15:01:27.0158 1712 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    15:01:27.0173 1712 NetTcpPortSharing - ok
    15:01:27.0173 1712 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    15:01:27.0173 1712 nfrd960 - ok
    15:01:27.0189 1712 NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
    15:01:27.0189 1712 NisDrv - ok
    15:01:27.0205 1712 NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
    15:01:27.0205 1712 NisSrv - ok
    15:01:27.0220 1712 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
    15:01:27.0220 1712 NlaSvc - ok
    15:01:27.0236 1712 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    15:01:27.0236 1712 Npfs - ok
    15:01:27.0251 1712 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    15:01:27.0251 1712 nsi - ok
    15:01:27.0251 1712 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    15:01:27.0251 1712 nsiproxy - ok
    15:01:27.0329 1712 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
    15:01:27.0345 1712 Ntfs - ok
    15:01:27.0407 1712 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    15:01:27.0407 1712 Null - ok
    15:01:27.0423 1712 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
    15:01:27.0423 1712 nvraid - ok
    15:01:27.0439 1712 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
    15:01:27.0439 1712 nvstor - ok
    15:01:27.0454 1712 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
    15:01:27.0454 1712 nv_agp - ok
    15:01:27.0454 1712 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
    15:01:27.0454 1712 ohci1394 - ok
    15:01:27.0485 1712 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    15:01:27.0485 1712 p2pimsvc - ok
    15:01:27.0517 1712 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    15:01:27.0517 1712 p2psvc - ok
    15:01:27.0532 1712 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    15:01:27.0532 1712 Parport - ok
    15:01:27.0548 1712 partmgr (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
    15:01:27.0548 1712 partmgr - ok
    15:01:27.0563 1712 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    15:01:27.0579 1712 PcaSvc - ok
    15:01:27.0579 1712 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
    15:01:27.0579 1712 pci - ok
    15:01:27.0595 1712 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
    15:01:27.0595 1712 pciide - ok
    15:01:27.0610 1712 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    15:01:27.0610 1712 pcmcia - ok
    15:01:27.0610 1712 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    15:01:27.0610 1712 pcw - ok
    15:01:27.0626 1712 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    15:01:27.0641 1712 PEAUTH - ok
    15:01:27.0704 1712 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
    15:01:27.0719 1712 PeerDistSvc - ok
    15:01:27.0766 1712 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    15:01:27.0782 1712 PerfHost - ok
    15:01:27.0875 1712 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
    15:01:27.0891 1712 pla - ok
    15:01:27.0938 1712 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
    15:01:27.0938 1712 PlugPlay - ok
    15:01:27.0953 1712 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    15:01:27.0953 1712 PNRPAutoReg - ok
    15:01:27.0969 1712 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    15:01:27.0969 1712 PNRPsvc - ok
    15:01:28.0000 1712 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
    15:01:28.0000 1712 PolicyAgent - ok
    15:01:28.0031 1712 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    15:01:28.0031 1712 Power - ok
    15:01:28.0078 1712 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
    15:01:28.0078 1712 PptpMiniport - ok
    15:01:28.0078 1712 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    15:01:28.0078 1712 Processor - ok
    15:01:28.0109 1712 ProfSvc (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
    15:01:28.0109 1712 ProfSvc - ok
    15:01:28.0125 1712 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:28.0125 1712 ProtectedStorage - ok
    15:01:28.0141 1712 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
    15:01:28.0141 1712 Psched - ok
    15:01:28.0187 1712 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    15:01:28.0203 1712 ql2300 - ok
    15:01:28.0250 1712 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    15:01:28.0265 1712 ql40xx - ok
    15:01:28.0281 1712 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    15:01:28.0281 1712 QWAVE - ok
    15:01:28.0281 1712 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    15:01:28.0281 1712 QWAVEdrv - ok
    15:01:28.0297 1712 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    15:01:28.0297 1712 RasAcd - ok
    15:01:28.0312 1712 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    15:01:28.0312 1712 RasAgileVpn - ok
    15:01:28.0328 1712 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    15:01:28.0328 1712 RasAuto - ok
    15:01:28.0343 1712 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
    15:01:28.0343 1712 Rasl2tp - ok
    15:01:28.0359 1712 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
    15:01:28.0375 1712 RasMan - ok
    15:01:28.0375 1712 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    15:01:28.0375 1712 RasPppoe - ok
    15:01:28.0375 1712 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    15:01:28.0390 1712 RasSstp - ok
    15:01:28.0406 1712 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
    15:01:28.0406 1712 rdbss - ok
    15:01:28.0406 1712 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    15:01:28.0406 1712 rdpbus - ok
    15:01:28.0421 1712 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    15:01:28.0421 1712 RDPCDD - ok
    15:01:28.0437 1712 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
    15:01:28.0437 1712 RDPDR - ok
    15:01:28.0453 1712 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    15:01:28.0468 1712 RDPENCDD - ok
    15:01:28.0468 1712 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    15:01:28.0484 1712 RDPREFMP - ok
    15:01:28.0515 1712 RDPWD (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
    15:01:28.0531 1712 RDPWD - ok
    15:01:28.0531 1712 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
    15:01:28.0531 1712 rdyboost - ok
    15:01:28.0562 1712 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    15:01:28.0593 1712 RemoteAccess - ok
    15:01:28.0609 1712 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    15:01:28.0609 1712 RemoteRegistry - ok
    15:01:28.0624 1712 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    15:01:28.0624 1712 RpcEptMapper - ok
    15:01:28.0640 1712 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    15:01:28.0640 1712 RpcLocator - ok
    15:01:28.0671 1712 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    15:01:28.0671 1712 RpcSs - ok
    15:01:28.0671 1712 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    15:01:28.0671 1712 rspndr - ok
    15:01:28.0702 1712 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
    15:01:28.0702 1712 RTL8167 - ok
    15:01:28.0749 1712 RTL8187B (4a06585c8673f4458e9fbbc9dddb4d28) C:\Windows\system32\DRIVERS\wg111v3.sys
    15:01:28.0749 1712 RTL8187B - ok
    15:01:28.0765 1712 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
    15:01:28.0765 1712 s3cap - ok
    15:01:28.0780 1712 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:28.0780 1712 SamSs - ok
    15:01:28.0796 1712 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
    15:01:28.0796 1712 sbp2port - ok
    15:01:28.0811 1712 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    15:01:28.0827 1712 SCardSvr - ok
    15:01:28.0874 1712 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
    15:01:28.0874 1712 scfilter - ok
    15:01:28.0921 1712 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
    15:01:28.0952 1712 Schedule - ok
    15:01:28.0967 1712 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    15:01:28.0967 1712 SCPolicySvc - ok
    15:01:28.0983 1712 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
    15:01:28.0983 1712 SDRSVC - ok
    15:01:29.0014 1712 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    15:01:29.0014 1712 secdrv - ok
    15:01:29.0030 1712 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
    15:01:29.0030 1712 seclogon - ok
    15:01:29.0030 1712 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
    15:01:29.0030 1712 SENS - ok
    15:01:29.0045 1712 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    15:01:29.0045 1712 SensrSvc - ok
    15:01:29.0045 1712 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    15:01:29.0045 1712 Serenum - ok
    15:01:29.0045 1712 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    15:01:29.0045 1712 Serial - ok
    15:01:29.0061 1712 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    15:01:29.0061 1712 sermouse - ok
    15:01:29.0077 1712 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
    15:01:29.0077 1712 SessionEnv - ok
    15:01:29.0092 1712 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
    15:01:29.0092 1712 sffdisk - ok
    15:01:29.0092 1712 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
    15:01:29.0092 1712 sffp_mmc - ok
    15:01:29.0092 1712 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
    15:01:29.0092 1712 sffp_sd - ok
    15:01:29.0092 1712 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    15:01:29.0092 1712 sfloppy - ok
    15:01:29.0123 1712 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    15:01:29.0123 1712 SharedAccess - ok
    15:01:29.0155 1712 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
    15:01:29.0155 1712 ShellHWDetection - ok
    15:01:29.0155 1712 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    15:01:29.0155 1712 SiSRaid2 - ok
    15:01:29.0155 1712 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    15:01:29.0170 1712 SiSRaid4 - ok
    15:01:29.0201 1712 SkypeUpdate (f07af60b152221472fbdb2fecec4896d) C:\Program Files (x86)\Skype\Updater\Updater.exe
    15:01:29.0201 1712 SkypeUpdate - ok
    15:01:29.0217 1712 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    15:01:29.0217 1712 Smb - ok
    15:01:29.0233 1712 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    15:01:29.0233 1712 SNMPTRAP - ok
    15:01:29.0233 1712 SophosVirusRemovalTool - ok
    15:01:29.0248 1712 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    15:01:29.0248 1712 spldr - ok
    15:01:29.0279 1712 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
    15:01:29.0295 1712 Spooler - ok
    15:01:29.0435 1712 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
    15:01:29.0467 1712 sppsvc - ok
    15:01:29.0529 1712 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    15:01:29.0529 1712 sppuinotify - ok
    15:01:29.0560 1712 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
    15:01:29.0560 1712 srv - ok
    15:01:29.0591 1712 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
    15:01:29.0591 1712 srv2 - ok
    15:01:29.0607 1712 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
    15:01:29.0607 1712 srvnet - ok
    15:01:29.0623 1712 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    15:01:29.0638 1712 SSDPSRV - ok
    15:01:29.0638 1712 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    15:01:29.0638 1712 SstpSvc - ok
    15:01:29.0654 1712 Steam Client Service - ok
    15:01:29.0669 1712 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    15:01:29.0669 1712 stexstor - ok
    15:01:29.0716 1712 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
    15:01:29.0732 1712 stisvc - ok
    15:01:29.0747 1712 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
    15:01:29.0747 1712 storflt - ok
    15:01:29.0763 1712 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
    15:01:29.0763 1712 storvsc - ok
    15:01:29.0779 1712 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
    15:01:29.0779 1712 swenum - ok
    15:01:29.0810 1712 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    15:01:29.0825 1712 swprv - ok
    15:01:29.0888 1712 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
    15:01:29.0903 1712 SysMain - ok
    15:01:29.0966 1712 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
    15:01:29.0966 1712 TabletInputService - ok
    15:01:29.0981 1712 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
    15:01:29.0981 1712 TapiSrv - ok
    15:01:29.0997 1712 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    15:01:29.0997 1712 TBS - ok
    15:01:30.0091 1712 Tcpip (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
    15:01:30.0106 1712 Tcpip - ok
    15:01:30.0200 1712 TCPIP6 (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
    15:01:30.0215 1712 TCPIP6 - ok
    15:01:30.0247 1712 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
    15:01:30.0247 1712 tcpipreg - ok
    15:01:30.0262 1712 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    15:01:30.0262 1712 TDPIPE - ok
    15:01:30.0278 1712 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
    15:01:30.0278 1712 TDTCP - ok
    15:01:30.0293 1712 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
    15:01:30.0293 1712 tdx - ok
    15:01:30.0293 1712 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
    15:01:30.0293 1712 TermDD - ok
    15:01:30.0340 1712 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
    15:01:30.0356 1712 TermService - ok
    15:01:30.0356 1712 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    15:01:30.0356 1712 Themes - ok
    15:01:30.0387 1712 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    15:01:30.0387 1712 THREADORDER - ok
    15:01:30.0403 1712 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    15:01:30.0403 1712 TrkWks - ok
    15:01:30.0434 1712 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
    15:01:30.0434 1712 TrustedInstaller - ok
    15:01:30.0434 1712 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
    15:01:30.0434 1712 tssecsrv - ok
    15:01:30.0449 1712 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
    15:01:30.0449 1712 tunnel - ok
    15:01:30.0465 1712 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    15:01:30.0465 1712 uagp35 - ok
    15:01:30.0481 1712 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
    15:01:30.0481 1712 udfs - ok
    15:01:30.0481 1712 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    15:01:30.0496 1712 UI0Detect - ok
    15:01:30.0496 1712 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
    15:01:30.0496 1712 uliagpkx - ok
    15:01:30.0512 1712 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
    15:01:30.0512 1712 umbus - ok
    15:01:30.0527 1712 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    15:01:30.0527 1712 UmPass - ok
    15:01:30.0543 1712 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
    15:01:30.0543 1712 UmRdpService - ok
    15:01:30.0574 1712 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    15:01:30.0574 1712 upnphost - ok
    15:01:30.0590 1712 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
    15:01:30.0590 1712 usbccgp - ok
    15:01:30.0605 1712 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    15:01:30.0605 1712 usbcir - ok
    15:01:30.0605 1712 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
    15:01:30.0605 1712 usbehci - ok
    15:01:30.0621 1712 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
    15:01:30.0637 1712 usbhub - ok
    15:01:30.0637 1712 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
    15:01:30.0637 1712 usbohci - ok
    15:01:30.0637 1712 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    15:01:30.0637 1712 usbprint - ok
    15:01:30.0637 1712 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    15:01:30.0637 1712 USBSTOR - ok
    15:01:30.0652 1712 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
    15:01:30.0652 1712 usbuhci - ok
    15:01:30.0668 1712 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    15:01:30.0668 1712 UxSms - ok
    15:01:30.0683 1712 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:30.0683 1712 VaultSvc - ok
    15:01:30.0683 1712 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
    15:01:30.0683 1712 vdrvroot - ok
    15:01:30.0715 1712 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
    15:01:30.0730 1712 vds - ok
    15:01:30.0730 1712 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    15:01:30.0730 1712 vga - ok
    15:01:30.0730 1712 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    15:01:30.0730 1712 VgaSave - ok
    15:01:30.0761 1712 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
    15:01:30.0761 1712 vhdmp - ok
    15:01:30.0777 1712 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
    15:01:30.0777 1712 viaide - ok
    15:01:30.0793 1712 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
    15:01:30.0793 1712 vmbus - ok
    15:01:30.0808 1712 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
    15:01:30.0808 1712 VMBusHID - ok
    15:01:30.0808 1712 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
    15:01:30.0808 1712 volmgr - ok
    15:01:30.0824 1712 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
    15:01:30.0824 1712 volmgrx - ok
    15:01:30.0839 1712 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
    15:01:30.0839 1712 volsnap - ok
    15:01:30.0855 1712 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    15:01:30.0855 1712 vsmraid - ok
    15:01:30.0933 1712 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
    15:01:30.0949 1712 VSS - ok
    15:01:31.0011 1712 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
    15:01:31.0011 1712 vwifibus - ok
    15:01:31.0027 1712 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    15:01:31.0027 1712 vwififlt - ok
    15:01:31.0042 1712 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    15:01:31.0042 1712 W32Time - ok
    15:01:31.0042 1712 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    15:01:31.0042 1712 WacomPen - ok
    15:01:31.0058 1712 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    15:01:31.0058 1712 WANARP - ok
    15:01:31.0058 1712 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    15:01:31.0058 1712 Wanarpv6 - ok
    15:01:31.0136 1712 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    15:01:31.0354 1712 WatAdminSvc - ok
    15:01:31.0417 1712 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
    15:01:31.0432 1712 wbengine - ok
    15:01:31.0463 1712 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    15:01:31.0463 1712 WbioSrvc - ok
    15:01:31.0495 1712 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
    15:01:31.0510 1712 wcncsvc - ok
    15:01:31.0526 1712 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    15:01:31.0526 1712 WcsPlugInService - ok
    15:01:31.0541 1712 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    15:01:31.0541 1712 Wd - ok
    15:01:31.0557 1712 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    15:01:31.0573 1712 Wdf01000 - ok
    15:01:31.0573 1712 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    15:01:31.0573 1712 WdiServiceHost - ok
    15:01:31.0588 1712 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    15:01:31.0588 1712 WdiSystemHost - ok
    15:01:31.0604 1712 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
    15:01:31.0619 1712 WebClient - ok
    15:01:31.0635 1712 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    15:01:31.0635 1712 Wecsvc - ok
    15:01:31.0651 1712 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    15:01:31.0651 1712 wercplsupport - ok
    15:01:31.0666 1712 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    15:01:31.0666 1712 WerSvc - ok
    15:01:31.0682 1712 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    15:01:31.0682 1712 WfpLwf - ok
    15:01:31.0697 1712 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    15:01:31.0697 1712 WIMMount - ok
    15:01:31.0713 1712 WinDefend - ok
    15:01:31.0713 1712 WinHttpAutoProxySvc - ok
    15:01:31.0760 1712 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    15:01:31.0760 1712 Winmgmt - ok
    15:01:31.0853 1712 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
    15:01:31.0869 1712 WinRM - ok
    15:01:31.0963 1712 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    15:01:31.0978 1712 Wlansvc - ok
    15:01:31.0994 1712 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
    15:01:31.0994 1712 WmiAcpi - ok
    15:01:32.0009 1712 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    15:01:32.0025 1712 wmiApSrv - ok
     
  9. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    15:01:32.0025 1712 WMPNetworkSvc - ok
    15:01:32.0041 1712 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    15:01:32.0041 1712 WPCSvc - ok
    15:01:32.0056 1712 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
    15:01:32.0056 1712 WPDBusEnum - ok
    15:01:32.0056 1712 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    15:01:32.0056 1712 ws2ifsl - ok
    15:01:32.0087 1712 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
    15:01:32.0087 1712 wscsvc - ok
    15:01:32.0087 1712 WSearch - ok
    15:01:32.0181 1712 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
    15:01:32.0212 1712 wuauserv - ok
    15:01:32.0259 1712 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
    15:01:32.0259 1712 WudfPf - ok
    15:01:32.0275 1712 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
    15:01:32.0275 1712 WUDFRd - ok
    15:01:32.0306 1712 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
    15:01:32.0306 1712 wudfsvc - ok
    15:01:32.0321 1712 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    15:01:32.0353 1712 WwanSvc - ok
    15:01:32.0368 1712 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    15:01:32.0524 1712 \Device\Harddisk0\DR0 - ok
    15:01:32.0555 1712 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
    15:01:32.0555 1712 \Device\Harddisk1\DR1 - ok
    15:01:32.0555 1712 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
    15:01:32.0711 1712 \Device\Harddisk2\DR2 - ok
    15:01:32.0727 1712 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk3\DR3
    15:01:33.0164 1712 \Device\Harddisk3\DR3 - ok
    15:01:33.0164 1712 Boot (0x1200) (340d77b4b299b15de4aeddc71bd98243) \Device\Harddisk0\DR0\Partition0
    15:01:33.0164 1712 \Device\Harddisk0\DR0\Partition0 - ok
    15:01:33.0179 1712 Boot (0x1200) (0b77a4731e9214b03b40393561cadf78) \Device\Harddisk0\DR0\Partition1
    15:01:33.0179 1712 \Device\Harddisk0\DR0\Partition1 - ok
    15:01:33.0195 1712 Boot (0x1200) (5c3c71018f858b123a4b9d9a40a3fcd0) \Device\Harddisk1\DR1\Partition0
    15:01:33.0195 1712 \Device\Harddisk1\DR1\Partition0 - ok
    15:01:33.0195 1712 Boot (0x1200) (631f69621fb28148eb2711a4d3a7ac6d) \Device\Harddisk2\DR2\Partition0
    15:01:33.0195 1712 \Device\Harddisk2\DR2\Partition0 - ok
    15:01:33.0195 1712 Boot (0x1200) (dd8321872998b646b1eefa8f126ec27c) \Device\Harddisk2\DR2\Partition1
    15:01:33.0195 1712 \Device\Harddisk2\DR2\Partition1 - ok
    15:01:33.0211 1712 Boot (0x1200) (6372452f237b6fdb4df9440c823a3859) \Device\Harddisk3\DR3\Partition0
    15:01:33.0211 1712 \Device\Harddisk3\DR3\Partition0 - ok
    15:01:33.0211 1712 ============================================================
    15:01:33.0211 1712 Scan finished
    15:01:33.0211 1712 ============================================================
    15:01:33.0211 3028 Detected object count: 0
    15:01:33.0211 3028 Actual detected object count: 0
    15:01:45.0784 0676 ============================================================
    15:01:45.0784 0676 Scan started
    15:01:45.0784 0676 Mode: Manual; SigCheck; TDLFS;
    15:01:45.0784 0676 ============================================================
    15:01:46.0018 0676 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
    15:01:46.0081 0676 1394ohci - ok
    15:01:46.0081 0676 54556415 - ok
    15:01:46.0096 0676 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
    15:01:46.0112 0676 ACPI - ok
    15:01:46.0112 0676 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
    15:01:46.0159 0676 AcpiPmi - ok
    15:01:46.0221 0676 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    15:01:46.0237 0676 AdobeFlashPlayerUpdateSvc - ok
    15:01:46.0252 0676 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    15:01:46.0268 0676 adp94xx - ok
    15:01:46.0284 0676 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    15:01:46.0299 0676 adpahci - ok
    15:01:46.0315 0676 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    15:01:46.0330 0676 adpu320 - ok
    15:01:46.0346 0676 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    15:01:46.0377 0676 AeLookupSvc - ok
    15:01:46.0424 0676 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
    15:01:46.0440 0676 AFD - ok
    15:01:46.0455 0676 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
    15:01:46.0455 0676 agp440 - ok
    15:01:46.0471 0676 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    15:01:46.0502 0676 ALG - ok
    15:01:46.0518 0676 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
    15:01:46.0518 0676 aliide - ok
    15:01:46.0549 0676 AMD External Events Utility (9c616ba191b80f5cd1a1b9553e107100) C:\Windows\system32\atiesrxx.exe
    15:01:46.0596 0676 AMD External Events Utility - ok
    15:01:46.0596 0676 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
    15:01:46.0596 0676 amdide - ok
    15:01:46.0611 0676 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    15:01:46.0627 0676 AmdK8 - ok
    15:01:47.0001 0676 amdkmdag (5165e83751b8ff40e5e4925996fcc506) C:\Windows\system32\DRIVERS\atikmdag.sys
    15:01:47.0095 0676 amdkmdag - ok
    15:01:47.0173 0676 amdkmdap (86ab3cf484260c4318f3a6e8b035f422) C:\Windows\system32\DRIVERS\atikmpag.sys
    15:01:47.0188 0676 amdkmdap - ok
    15:01:47.0188 0676 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    15:01:47.0204 0676 AmdPPM - ok
    15:01:47.0235 0676 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
    15:01:47.0235 0676 amdsata - ok
    15:01:47.0282 0676 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    15:01:47.0282 0676 amdsbs - ok
    15:01:47.0298 0676 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
    15:01:47.0298 0676 amdxata - ok
    15:01:47.0313 0676 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
    15:01:47.0360 0676 AppID - ok
    15:01:47.0376 0676 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    15:01:47.0407 0676 AppIDSvc - ok
    15:01:47.0422 0676 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
    15:01:47.0438 0676 Appinfo - ok
    15:01:47.0454 0676 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
    15:01:47.0485 0676 AppMgmt - ok
    15:01:47.0500 0676 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    15:01:47.0500 0676 arc - ok
    15:01:47.0516 0676 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    15:01:47.0516 0676 arcsas - ok
    15:01:47.0516 0676 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    15:01:47.0547 0676 AsyncMac - ok
    15:01:47.0547 0676 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
    15:01:47.0563 0676 atapi - ok
    15:01:47.0578 0676 AtiHDAudioService (24464b908e143d2561e9e452fee97309) C:\Windows\system32\drivers\AtihdW76.sys
    15:01:47.0610 0676 AtiHDAudioService - ok
    15:01:47.0641 0676 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    15:01:47.0688 0676 AudioEndpointBuilder - ok
    15:01:47.0688 0676 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    15:01:47.0719 0676 AudioSrv - ok
    15:01:47.0734 0676 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
    15:01:47.0750 0676 AxInstSV - ok
    15:01:47.0781 0676 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    15:01:47.0812 0676 b06bdrv - ok
    15:01:47.0828 0676 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    15:01:47.0844 0676 b57nd60a - ok
    15:01:47.0844 0676 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    15:01:47.0875 0676 BDESVC - ok
    15:01:47.0875 0676 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    15:01:47.0906 0676 Beep - ok
    15:01:47.0937 0676 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
    15:01:47.0968 0676 BFE - ok
    15:01:48.0015 0676 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
    15:01:48.0046 0676 BITS - ok
    15:01:48.0093 0676 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    15:01:48.0109 0676 blbdrive - ok
    15:01:48.0124 0676 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
    15:01:48.0156 0676 bowser - ok
    15:01:48.0156 0676 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    15:01:48.0171 0676 BrFiltLo - ok
    15:01:48.0171 0676 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    15:01:48.0187 0676 BrFiltUp - ok
    15:01:48.0202 0676 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
    15:01:48.0249 0676 Browser - ok
    15:01:48.0249 0676 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    15:01:48.0280 0676 Brserid - ok
    15:01:48.0280 0676 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    15:01:48.0296 0676 BrSerWdm - ok
    15:01:48.0296 0676 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    15:01:48.0312 0676 BrUsbMdm - ok
    15:01:48.0312 0676 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    15:01:48.0327 0676 BrUsbSer - ok
    15:01:48.0343 0676 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    15:01:48.0358 0676 BTHMODEM - ok
    15:01:48.0374 0676 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    15:01:48.0405 0676 bthserv - ok
    15:01:48.0405 0676 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    15:01:48.0436 0676 cdfs - ok
    15:01:48.0452 0676 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
    15:01:48.0468 0676 cdrom - ok
    15:01:48.0483 0676 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    15:01:48.0499 0676 CertPropSvc - ok
    15:01:48.0499 0676 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    15:01:48.0514 0676 circlass - ok
    15:01:48.0546 0676 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    15:01:48.0561 0676 CLFS - ok
    15:01:48.0608 0676 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    15:01:48.0608 0676 clr_optimization_v2.0.50727_32 - ok
    15:01:48.0639 0676 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    15:01:48.0655 0676 clr_optimization_v2.0.50727_64 - ok
    15:01:48.0686 0676 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    15:01:48.0702 0676 clr_optimization_v4.0.30319_32 - ok
    15:01:48.0717 0676 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    15:01:48.0717 0676 clr_optimization_v4.0.30319_64 - ok
    15:01:48.0717 0676 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    15:01:48.0733 0676 CmBatt - ok
    15:01:48.0764 0676 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
    15:01:48.0764 0676 cmdide - ok
    15:01:48.0795 0676 CNG (ca7720b73446fddec5c69519c1174c98) C:\Windows\system32\Drivers\cng.sys
    15:01:48.0811 0676 CNG - ok
    15:01:48.0826 0676 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    15:01:48.0826 0676 Compbatt - ok
    15:01:48.0842 0676 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
    15:01:48.0858 0676 CompositeBus - ok
    15:01:48.0858 0676 COMSysApp - ok
    15:01:48.0858 0676 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    15:01:48.0873 0676 crcdisk - ok
    15:01:48.0889 0676 CryptSvc (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
    15:01:48.0920 0676 CryptSvc - ok
    15:01:48.0951 0676 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
    15:01:48.0982 0676 CSC - ok
    15:01:48.0998 0676 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
    15:01:49.0029 0676 CscService - ok
    15:01:49.0076 0676 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    15:01:49.0123 0676 DcomLaunch - ok
    15:01:49.0138 0676 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    15:01:49.0185 0676 defragsvc - ok
    15:01:49.0216 0676 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
    15:01:49.0232 0676 DfsC - ok
    15:01:49.0248 0676 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
    15:01:49.0294 0676 Dhcp - ok
    15:01:49.0310 0676 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    15:01:49.0341 0676 discache - ok
    15:01:49.0341 0676 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    15:01:49.0357 0676 Disk - ok
    15:01:49.0372 0676 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
    15:01:49.0404 0676 Dnscache - ok
    15:01:49.0419 0676 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
    15:01:49.0435 0676 dot3svc - ok
    15:01:49.0450 0676 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
    15:01:49.0497 0676 DPS - ok
    15:01:49.0497 0676 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    15:01:49.0513 0676 drmkaud - ok
    15:01:49.0560 0676 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
    15:01:49.0575 0676 DXGKrnl - ok
    15:01:49.0591 0676 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    15:01:49.0622 0676 EapHost - ok
    15:01:49.0747 0676 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    15:01:49.0778 0676 ebdrv - ok
    15:01:49.0856 0676 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
    15:01:49.0887 0676 EFS - ok
    15:01:49.0934 0676 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
    15:01:49.0950 0676 ehRecvr - ok
    15:01:49.0965 0676 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    15:01:49.0981 0676 ehSched - ok
    15:01:50.0012 0676 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    15:01:50.0028 0676 elxstor - ok
    15:01:50.0028 0676 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
    15:01:50.0043 0676 ErrDev - ok
    15:01:50.0074 0676 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    15:01:50.0106 0676 EventSystem - ok
    15:01:50.0121 0676 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    15:01:50.0137 0676 exfat - ok
    15:01:50.0168 0676 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    15:01:50.0184 0676 fastfat - ok
    15:01:50.0230 0676 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
    15:01:50.0246 0676 Fax - ok
    15:01:50.0262 0676 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    15:01:50.0262 0676 fdc - ok
    15:01:50.0277 0676 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    15:01:50.0324 0676 fdPHost - ok
    15:01:50.0340 0676 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    15:01:50.0371 0676 FDResPub - ok
    15:01:50.0386 0676 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    15:01:50.0402 0676 FileInfo - ok
    15:01:50.0402 0676 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    15:01:50.0433 0676 Filetrace - ok
    15:01:50.0433 0676 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    15:01:50.0433 0676 flpydisk - ok
    15:01:50.0464 0676 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
    15:01:50.0480 0676 FltMgr - ok
    15:01:50.0542 0676 FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
    15:01:50.0558 0676 FontCache - ok
    15:01:50.0589 0676 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    15:01:50.0605 0676 FontCache3.0.0.0 - ok
    15:01:50.0605 0676 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    15:01:50.0620 0676 FsDepends - ok
    15:01:50.0636 0676 Fs_Rec (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
    15:01:50.0636 0676 Fs_Rec - ok
    15:01:50.0667 0676 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
    15:01:50.0683 0676 fvevol - ok
    15:01:50.0698 0676 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    15:01:50.0698 0676 gagp30kx - ok
    15:01:50.0745 0676 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
    15:01:50.0776 0676 gpsvc - ok
    15:01:50.0792 0676 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    15:01:50.0823 0676 hcw85cir - ok
    15:01:50.0854 0676 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
    15:01:50.0870 0676 HdAudAddService - ok
    15:01:50.0886 0676 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    15:01:50.0901 0676 HDAudBus - ok
    15:01:50.0964 0676 HDDHealth (354f7ac7ae454a1daf85bf7c0ffefd07) C:\Program Files (x86)\HDD Health\HDDHealthService.exe
    15:01:50.0964 0676 HDDHealth - ok
    15:01:50.0979 0676 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    15:01:50.0995 0676 HidBatt - ok
    15:01:50.0995 0676 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    15:01:51.0010 0676 HidBth - ok
    15:01:51.0010 0676 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    15:01:51.0026 0676 HidIr - ok
    15:01:51.0042 0676 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
    15:01:51.0057 0676 hidserv - ok
    15:01:51.0073 0676 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
    15:01:51.0088 0676 HidUsb - ok
    15:01:51.0104 0676 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
    15:01:51.0135 0676 hkmsvc - ok
    15:01:51.0151 0676 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
    15:01:51.0166 0676 HomeGroupListener - ok
    15:01:51.0182 0676 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
    15:01:51.0198 0676 HomeGroupProvider - ok
    15:01:51.0213 0676 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
    15:01:51.0229 0676 HpSAMD - ok
    15:01:51.0260 0676 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
    15:01:51.0291 0676 HTTP - ok
    15:01:51.0291 0676 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
    15:01:51.0307 0676 hwpolicy - ok
    15:01:51.0322 0676 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    15:01:51.0322 0676 i8042prt - ok
    15:01:51.0338 0676 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
    15:01:51.0354 0676 iaStorV - ok
    15:01:51.0416 0676 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    15:01:51.0432 0676 idsvc - ok
    15:01:51.0432 0676 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    15:01:51.0447 0676 iirsp - ok
    15:01:51.0494 0676 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
    15:01:51.0510 0676 IKEEXT - ok
    15:01:51.0525 0676 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
    15:01:51.0541 0676 intelide - ok
    15:01:51.0541 0676 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    15:01:51.0556 0676 intelppm - ok
    15:01:51.0556 0676 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    15:01:51.0588 0676 IPBusEnum - ok
    15:01:51.0603 0676 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    15:01:51.0634 0676 IpFilterDriver - ok
    15:01:51.0666 0676 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
    15:01:51.0697 0676 iphlpsvc - ok
    15:01:51.0697 0676 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
    15:01:51.0712 0676 IPMIDRV - ok
    15:01:51.0728 0676 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    15:01:51.0759 0676 IPNAT - ok
    15:01:51.0759 0676 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    15:01:51.0775 0676 IRENUM - ok
    15:01:51.0775 0676 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
    15:01:51.0790 0676 isapnp - ok
    15:01:51.0806 0676 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
    15:01:51.0806 0676 iScsiPrt - ok
    15:01:51.0822 0676 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    15:01:51.0837 0676 kbdclass - ok
    15:01:51.0837 0676 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
    15:01:51.0868 0676 kbdhid - ok
    15:01:51.0884 0676 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:51.0884 0676 KeyIso - ok
    15:01:51.0900 0676 KSecDD (4f4b5fde429416877de7143044582eb5) C:\Windows\system32\Drivers\ksecdd.sys
    15:01:51.0915 0676 KSecDD - ok
    15:01:51.0915 0676 KSecPkg (6f40465a44ecdc1731befafec5bdd03c) C:\Windows\system32\Drivers\ksecpkg.sys
    15:01:51.0931 0676 KSecPkg - ok
    15:01:51.0931 0676 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    15:01:51.0962 0676 ksthunk - ok
    15:01:51.0978 0676 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    15:01:52.0024 0676 KtmRm - ok
    15:01:52.0040 0676 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
    15:01:52.0071 0676 LanmanServer - ok
    15:01:52.0087 0676 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
    15:01:52.0118 0676 LanmanWorkstation - ok
    15:01:52.0118 0676 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    15:01:52.0149 0676 lltdio - ok
    15:01:52.0165 0676 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    15:01:52.0196 0676 lltdsvc - ok
    15:01:52.0196 0676 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    15:01:52.0227 0676 lmhosts - ok
    15:01:52.0227 0676 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    15:01:52.0243 0676 LSI_FC - ok
    15:01:52.0258 0676 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    15:01:52.0258 0676 LSI_SAS - ok
    15:01:52.0274 0676 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    15:01:52.0274 0676 LSI_SAS2 - ok
    15:01:52.0290 0676 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    15:01:52.0290 0676 LSI_SCSI - ok
    15:01:52.0290 0676 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    15:01:52.0321 0676 luafv - ok
    15:01:52.0336 0676 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
    15:01:52.0352 0676 MBAMProtector - ok
    15:01:52.0414 0676 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    15:01:52.0430 0676 MBAMService - ok
    15:01:52.0446 0676 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
    15:01:52.0461 0676 Mcx2Svc - ok
    15:01:52.0461 0676 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    15:01:52.0477 0676 megasas - ok
    15:01:52.0492 0676 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    15:01:52.0492 0676 MegaSR - ok
    15:01:52.0524 0676 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    15:01:52.0586 0676 MMCSS - ok
    15:01:52.0602 0676 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    15:01:52.0633 0676 Modem - ok
    15:01:52.0633 0676 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    15:01:52.0648 0676 monitor - ok
    15:01:52.0648 0676 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    15:01:52.0648 0676 mouclass - ok
    15:01:52.0648 0676 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    15:01:52.0664 0676 mouhid - ok
    15:01:52.0664 0676 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
    15:01:52.0680 0676 mountmgr - ok
    15:01:52.0695 0676 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
     
  10. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    15:01:52.0711 0676 MozillaMaintenance - ok
    15:01:52.0726 0676 MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
    15:01:52.0742 0676 MpFilter - ok
    15:01:52.0742 0676 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
    15:01:52.0758 0676 mpio - ok
    15:01:52.0758 0676 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    15:01:52.0789 0676 mpsdrv - ok
    15:01:52.0820 0676 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
    15:01:52.0851 0676 MpsSvc - ok
    15:01:52.0867 0676 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
    15:01:52.0882 0676 MRxDAV - ok
    15:01:52.0898 0676 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
    15:01:52.0929 0676 mrxsmb - ok
    15:01:52.0960 0676 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    15:01:52.0960 0676 mrxsmb10 - ok
    15:01:52.0976 0676 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    15:01:52.0992 0676 mrxsmb20 - ok
    15:01:53.0007 0676 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
    15:01:53.0007 0676 msahci - ok
    15:01:53.0023 0676 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
    15:01:53.0023 0676 msdsm - ok
    15:01:53.0054 0676 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    15:01:53.0054 0676 MSDTC - ok
    15:01:53.0070 0676 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    15:01:53.0101 0676 Msfs - ok
    15:01:53.0101 0676 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    15:01:53.0132 0676 mshidkmdf - ok
    15:01:53.0148 0676 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
    15:01:53.0163 0676 msisadrv - ok
    15:01:53.0163 0676 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    15:01:53.0194 0676 MSiSCSI - ok
    15:01:53.0194 0676 msiserver - ok
    15:01:53.0210 0676 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    15:01:53.0241 0676 MSKSSRV - ok
    15:01:53.0272 0676 MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
    15:01:53.0272 0676 MsMpSvc - ok
    15:01:53.0288 0676 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    15:01:53.0304 0676 MSPCLOCK - ok
    15:01:53.0304 0676 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    15:01:53.0335 0676 MSPQM - ok
    15:01:53.0350 0676 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
    15:01:53.0366 0676 MsRPC - ok
    15:01:53.0366 0676 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
    15:01:53.0382 0676 mssmbios - ok
    15:01:53.0382 0676 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    15:01:53.0413 0676 MSTEE - ok
    15:01:53.0428 0676 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    15:01:53.0444 0676 MTConfig - ok
    15:01:53.0444 0676 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    15:01:53.0444 0676 Mup - ok
    15:01:53.0491 0676 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
    15:01:53.0506 0676 napagent - ok
    15:01:53.0538 0676 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    15:01:53.0553 0676 NativeWifiP - ok
    15:01:53.0600 0676 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
    15:01:53.0616 0676 NDIS - ok
    15:01:53.0616 0676 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    15:01:53.0647 0676 NdisCap - ok
    15:01:53.0647 0676 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    15:01:53.0678 0676 NdisTapi - ok
    15:01:53.0678 0676 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
    15:01:53.0709 0676 Ndisuio - ok
    15:01:53.0725 0676 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
    15:01:53.0740 0676 NdisWan - ok
    15:01:53.0740 0676 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
    15:01:53.0772 0676 NDProxy - ok
    15:01:53.0772 0676 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    15:01:53.0803 0676 NetBIOS - ok
    15:01:53.0803 0676 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
    15:01:53.0834 0676 NetBT - ok
    15:01:53.0850 0676 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:53.0850 0676 Netlogon - ok
    15:01:53.0881 0676 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    15:01:53.0928 0676 Netman - ok
    15:01:53.0943 0676 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    15:01:53.0959 0676 netprofm - ok
    15:01:53.0990 0676 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    15:01:54.0006 0676 NetTcpPortSharing - ok
    15:01:54.0006 0676 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    15:01:54.0021 0676 nfrd960 - ok
    15:01:54.0037 0676 NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
    15:01:54.0052 0676 NisDrv - ok
    15:01:54.0099 0676 NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
    15:01:54.0099 0676 NisSrv - ok
    15:01:54.0130 0676 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
    15:01:54.0162 0676 NlaSvc - ok
    15:01:54.0162 0676 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    15:01:54.0193 0676 Npfs - ok
    15:01:54.0208 0676 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    15:01:54.0224 0676 nsi - ok
    15:01:54.0224 0676 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    15:01:54.0271 0676 nsiproxy - ok
    15:01:54.0318 0676 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
    15:01:54.0349 0676 Ntfs - ok
    15:01:54.0411 0676 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    15:01:54.0458 0676 Null - ok
    15:01:54.0458 0676 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
    15:01:54.0474 0676 nvraid - ok
    15:01:54.0474 0676 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
    15:01:54.0489 0676 nvstor - ok
    15:01:54.0505 0676 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
    15:01:54.0505 0676 nv_agp - ok
    15:01:54.0505 0676 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
    15:01:54.0520 0676 ohci1394 - ok
    15:01:54.0552 0676 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    15:01:54.0567 0676 p2pimsvc - ok
    15:01:54.0598 0676 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    15:01:54.0614 0676 p2psvc - ok
    15:01:54.0614 0676 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    15:01:54.0630 0676 Parport - ok
    15:01:54.0645 0676 partmgr (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
    15:01:54.0661 0676 partmgr - ok
    15:01:54.0676 0676 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    15:01:54.0692 0676 PcaSvc - ok
    15:01:54.0692 0676 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
    15:01:54.0708 0676 pci - ok
    15:01:54.0723 0676 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
    15:01:54.0723 0676 pciide - ok
    15:01:54.0739 0676 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    15:01:54.0739 0676 pcmcia - ok
    15:01:54.0754 0676 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    15:01:54.0754 0676 pcw - ok
    15:01:54.0786 0676 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    15:01:54.0817 0676 PEAUTH - ok
    15:01:54.0879 0676 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
    15:01:54.0910 0676 PeerDistSvc - ok
    15:01:54.0957 0676 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    15:01:54.0973 0676 PerfHost - ok
    15:01:55.0066 0676 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
    15:01:55.0098 0676 pla - ok
    15:01:55.0144 0676 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
    15:01:55.0176 0676 PlugPlay - ok
    15:01:55.0176 0676 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    15:01:55.0191 0676 PNRPAutoReg - ok
    15:01:55.0222 0676 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    15:01:55.0222 0676 PNRPsvc - ok
    15:01:55.0254 0676 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
    15:01:55.0300 0676 PolicyAgent - ok
    15:01:55.0316 0676 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    15:01:55.0363 0676 Power - ok
    15:01:55.0394 0676 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
    15:01:55.0410 0676 PptpMiniport - ok
    15:01:55.0425 0676 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    15:01:55.0441 0676 Processor - ok
    15:01:55.0456 0676 ProfSvc (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
    15:01:55.0472 0676 ProfSvc - ok
    15:01:55.0488 0676 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:55.0503 0676 ProtectedStorage - ok
    15:01:55.0503 0676 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
    15:01:55.0534 0676 Psched - ok
    15:01:55.0597 0676 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    15:01:55.0612 0676 ql2300 - ok
    15:01:55.0659 0676 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    15:01:55.0675 0676 ql40xx - ok
    15:01:55.0690 0676 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    15:01:55.0706 0676 QWAVE - ok
    15:01:55.0706 0676 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    15:01:55.0722 0676 QWAVEdrv - ok
    15:01:55.0737 0676 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    15:01:55.0753 0676 RasAcd - ok
    15:01:55.0768 0676 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    15:01:55.0800 0676 RasAgileVpn - ok
    15:01:55.0831 0676 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    15:01:55.0862 0676 RasAuto - ok
    15:01:55.0862 0676 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
    15:01:55.0893 0676 Rasl2tp - ok
    15:01:55.0909 0676 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
    15:01:55.0956 0676 RasMan - ok
    15:01:55.0956 0676 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    15:01:56.0002 0676 RasPppoe - ok
    15:01:56.0002 0676 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    15:01:56.0049 0676 RasSstp - ok
    15:01:56.0049 0676 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
    15:01:56.0080 0676 rdbss - ok
    15:01:56.0080 0676 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    15:01:56.0112 0676 rdpbus - ok
    15:01:56.0112 0676 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    15:01:56.0143 0676 RDPCDD - ok
    15:01:56.0158 0676 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
    15:01:56.0190 0676 RDPDR - ok
    15:01:56.0205 0676 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    15:01:56.0236 0676 RDPENCDD - ok
    15:01:56.0252 0676 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    15:01:56.0268 0676 RDPREFMP - ok
    15:01:56.0299 0676 RDPWD (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
    15:01:56.0330 0676 RDPWD - ok
    15:01:56.0346 0676 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
    15:01:56.0346 0676 rdyboost - ok
    15:01:56.0377 0676 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    15:01:56.0408 0676 RemoteAccess - ok
    15:01:56.0439 0676 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    15:01:56.0455 0676 RemoteRegistry - ok
    15:01:56.0470 0676 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    15:01:56.0502 0676 RpcEptMapper - ok
    15:01:56.0517 0676 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    15:01:56.0533 0676 RpcLocator - ok
    15:01:56.0564 0676 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    15:01:56.0580 0676 RpcSs - ok
    15:01:56.0595 0676 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    15:01:56.0626 0676 rspndr - ok
    15:01:56.0642 0676 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
    15:01:56.0658 0676 RTL8167 - ok
    15:01:56.0689 0676 RTL8187B (4a06585c8673f4458e9fbbc9dddb4d28) C:\Windows\system32\DRIVERS\wg111v3.sys
    15:01:56.0720 0676 RTL8187B - ok
    15:01:56.0736 0676 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
    15:01:56.0751 0676 s3cap - ok
    15:01:56.0767 0676 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:56.0767 0676 SamSs - ok
    15:01:56.0782 0676 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
    15:01:56.0782 0676 sbp2port - ok
    15:01:56.0814 0676 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    15:01:56.0829 0676 SCardSvr - ok
    15:01:56.0845 0676 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
    15:01:56.0892 0676 scfilter - ok
    15:01:56.0954 0676 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
    15:01:56.0985 0676 Schedule - ok
    15:01:57.0001 0676 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    15:01:57.0032 0676 SCPolicySvc - ok
    15:01:57.0048 0676 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
    15:01:57.0079 0676 SDRSVC - ok
    15:01:57.0094 0676 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    15:01:57.0110 0676 secdrv - ok
    15:01:57.0126 0676 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
    15:01:57.0141 0676 seclogon - ok
    15:01:57.0157 0676 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
    15:01:57.0188 0676 SENS - ok
    15:01:57.0188 0676 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    15:01:57.0204 0676 SensrSvc - ok
    15:01:57.0204 0676 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    15:01:57.0219 0676 Serenum - ok
    15:01:57.0235 0676 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    15:01:57.0235 0676 Serial - ok
    15:01:57.0250 0676 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    15:01:57.0266 0676 sermouse - ok
    15:01:57.0282 0676 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
    15:01:57.0313 0676 SessionEnv - ok
    15:01:57.0313 0676 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
    15:01:57.0328 0676 sffdisk - ok
    15:01:57.0328 0676 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
    15:01:57.0344 0676 sffp_mmc - ok
    15:01:57.0344 0676 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
    15:01:57.0360 0676 sffp_sd - ok
    15:01:57.0360 0676 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    15:01:57.0375 0676 sfloppy - ok
    15:01:57.0391 0676 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    15:01:57.0438 0676 SharedAccess - ok
    15:01:57.0453 0676 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
    15:01:57.0484 0676 ShellHWDetection - ok
    15:01:57.0484 0676 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    15:01:57.0500 0676 SiSRaid2 - ok
    15:01:57.0500 0676 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    15:01:57.0500 0676 SiSRaid4 - ok
    15:01:57.0531 0676 SkypeUpdate (f07af60b152221472fbdb2fecec4896d) C:\Program Files (x86)\Skype\Updater\Updater.exe
    15:01:57.0547 0676 SkypeUpdate - ok
    15:01:57.0547 0676 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    15:01:57.0578 0676 Smb - ok
    15:01:57.0578 0676 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    15:01:57.0594 0676 SNMPTRAP - ok
    15:01:57.0594 0676 SophosVirusRemovalTool - ok
    15:01:57.0609 0676 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    15:01:57.0609 0676 spldr - ok
    15:01:57.0656 0676 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
    15:01:57.0672 0676 Spooler - ok
    15:01:57.0828 0676 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
    15:01:57.0859 0676 sppsvc - ok
    15:01:57.0921 0676 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    15:01:57.0937 0676 sppuinotify - ok
    15:01:57.0984 0676 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
    15:01:57.0999 0676 srv - ok
    15:01:58.0030 0676 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
    15:01:58.0030 0676 srv2 - ok
    15:01:58.0046 0676 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
    15:01:58.0062 0676 srvnet - ok
    15:01:58.0093 0676 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    15:01:58.0108 0676 SSDPSRV - ok
    15:01:58.0124 0676 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    15:01:58.0140 0676 SstpSvc - ok
    15:01:58.0155 0676 Steam Client Service - ok
    15:01:58.0171 0676 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    15:01:58.0186 0676 stexstor - ok
    15:01:58.0218 0676 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
    15:01:58.0233 0676 stisvc - ok
    15:01:58.0249 0676 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
    15:01:58.0264 0676 storflt - ok
    15:01:58.0280 0676 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
    15:01:58.0280 0676 storvsc - ok
    15:01:58.0296 0676 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
    15:01:58.0296 0676 swenum - ok
    15:01:58.0327 0676 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    15:01:58.0374 0676 swprv - ok
    15:01:58.0436 0676 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
    15:01:58.0467 0676 SysMain - ok
    15:01:58.0530 0676 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
    15:01:58.0545 0676 TabletInputService - ok
    15:01:58.0561 0676 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
    15:01:58.0592 0676 TapiSrv - ok
    15:01:58.0608 0676 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    15:01:58.0639 0676 TBS - ok
    15:01:58.0732 0676 Tcpip (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
    15:01:58.0764 0676 Tcpip - ok
    15:01:58.0857 0676 TCPIP6 (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
    15:01:58.0888 0676 TCPIP6 - ok
    15:01:58.0935 0676 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
    15:01:58.0951 0676 tcpipreg - ok
    15:01:58.0966 0676 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    15:01:58.0982 0676 TDPIPE - ok
    15:01:59.0013 0676 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
    15:01:59.0013 0676 TDTCP - ok
    15:01:59.0029 0676 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
    15:01:59.0060 0676 tdx - ok
    15:01:59.0060 0676 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
    15:01:59.0076 0676 TermDD - ok
    15:01:59.0107 0676 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
    15:01:59.0138 0676 TermService - ok
    15:01:59.0138 0676 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    15:01:59.0169 0676 Themes - ok
    15:01:59.0185 0676 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    15:01:59.0200 0676 THREADORDER - ok
    15:01:59.0216 0676 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    15:01:59.0247 0676 TrkWks - ok
    15:01:59.0278 0676 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
    15:01:59.0294 0676 TrustedInstaller - ok
    15:01:59.0294 0676 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
    15:01:59.0325 0676 tssecsrv - ok
    15:01:59.0325 0676 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
    15:01:59.0356 0676 tunnel - ok
    15:01:59.0356 0676 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    15:01:59.0372 0676 uagp35 - ok
    15:01:59.0388 0676 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
    15:01:59.0403 0676 udfs - ok
    15:01:59.0419 0676 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    15:01:59.0434 0676 UI0Detect - ok
    15:01:59.0434 0676 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
    15:01:59.0450 0676 uliagpkx - ok
    15:01:59.0450 0676 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
    15:01:59.0466 0676 umbus - ok
    15:01:59.0466 0676 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    15:01:59.0481 0676 UmPass - ok
    15:01:59.0512 0676 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
    15:01:59.0528 0676 UmRdpService - ok
    15:01:59.0544 0676 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    15:01:59.0575 0676 upnphost - ok
    15:01:59.0575 0676 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
    15:01:59.0590 0676 usbccgp - ok
    15:01:59.0606 0676 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    15:01:59.0606 0676 usbcir - ok
    15:01:59.0622 0676 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
    15:01:59.0622 0676 usbehci - ok
    15:01:59.0637 0676 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
    15:01:59.0653 0676 usbhub - ok
    15:01:59.0668 0676 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
    15:01:59.0668 0676 usbohci - ok
    15:01:59.0684 0676 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    15:01:59.0700 0676 usbprint - ok
    15:01:59.0700 0676 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    15:01:59.0715 0676 USBSTOR - ok
    15:01:59.0715 0676 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
    15:01:59.0715 0676 usbuhci - ok
    15:01:59.0731 0676 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    15:01:59.0762 0676 UxSms - ok
    15:01:59.0778 0676 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    15:01:59.0778 0676 VaultSvc - ok
    15:01:59.0778 0676 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
    15:01:59.0793 0676 vdrvroot - ok
    15:01:59.0824 0676 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
    15:01:59.0840 0676 vds - ok
    15:01:59.0840 0676 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    15:01:59.0856 0676 vga - ok
    15:01:59.0856 0676 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    15:01:59.0871 0676 VgaSave - ok
    15:01:59.0887 0676 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
    15:01:59.0887 0676 vhdmp - ok
    15:01:59.0902 0676 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
    15:01:59.0902 0676 viaide - ok
    15:01:59.0934 0676 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
    15:01:59.0934 0676 vmbus - ok
    15:01:59.0934 0676 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
    15:01:59.0949 0676 VMBusHID - ok
    15:01:59.0965 0676 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
    15:01:59.0965 0676 volmgr - ok
    15:01:59.0996 0676 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
    15:01:59.0996 0676 volmgrx - ok
    15:02:00.0012 0676 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
    15:02:00.0027 0676 volsnap - ok
    15:02:00.0043 0676 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    15:02:00.0043 0676 vsmraid - ok
    15:02:00.0105 0676 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
    15:02:00.0136 0676 VSS - ok
    15:02:00.0199 0676 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
    15:02:00.0214 0676 vwifibus - ok
    15:02:00.0214 0676 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    15:02:00.0230 0676 vwififlt - ok
    15:02:00.0261 0676 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    15:02:00.0277 0676 W32Time - ok
    15:02:00.0292 0676 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    15:02:00.0308 0676 WacomPen - ok
    15:02:00.0308 0676 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    15:02:00.0339 0676 WANARP - ok
    15:02:00.0339 0676 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    15:02:00.0370 0676 Wanarpv6 - ok
    15:02:00.0433 0676 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    15:02:00.0464 0676 WatAdminSvc - ok
    15:02:00.0526 0676 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
    15:02:00.0558 0676 wbengine - ok
    15:02:00.0604 0676 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    15:02:00.0620 0676 WbioSrvc - ok
    15:02:00.0651 0676 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
    15:02:00.0698 0676 wcncsvc - ok
    15:02:00.0714 0676 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    15:02:00.0729 0676 WcsPlugInService - ok
    15:02:00.0745 0676 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    15:02:00.0745 0676 Wd - ok
    15:02:00.0776 0676 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    15:02:00.0792 0676 Wdf01000 - ok
    15:02:00.0807 0676 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    15:02:00.0823 0676 WdiServiceHost - ok
    15:02:00.0838 0676 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    15:02:00.0838 0676 WdiSystemHost - ok
    15:02:00.0885 0676 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
    15:02:00.0901 0676 WebClient - ok
    15:02:00.0916 0676 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    15:02:00.0948 0676 Wecsvc - ok
    15:02:00.0963 0676 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    15:02:00.0979 0676 wercplsupport - ok
    15:02:00.0994 0676 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    15:02:01.0010 0676 WerSvc - ok
    15:02:01.0041 0676 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    15:02:01.0057 0676 WfpLwf - ok
    15:02:01.0072 0676 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    15:02:01.0072 0676 WIMMount - ok
    15:02:01.0088 0676 WinDefend - ok
    15:02:01.0104 0676 WinHttpAutoProxySvc - ok
    15:02:01.0150 0676 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    15:02:01.0166 0676 Winmgmt - ok
    15:02:01.0260 0676 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
    15:02:01.0306 0676 WinRM - ok
    15:02:01.0400 0676 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    15:02:01.0416 0676 Wlansvc - ok
    15:02:01.0416 0676 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
    15:02:01.0431 0676 WmiAcpi - ok
    15:02:01.0462 0676 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    15:02:01.0462 0676 wmiApSrv - ok
    15:02:01.0478 0676 WMPNetworkSvc - ok
    15:02:01.0494 0676 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    15:02:01.0509 0676 WPCSvc - ok
    15:02:01.0525 0676 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
    15:02:01.0540 0676 WPDBusEnum - ok
    15:02:01.0540 0676 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    15:02:01.0572 0676 ws2ifsl - ok
    15:02:01.0603 0676 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
    15:02:01.0603 0676 wscsvc - ok
    15:02:01.0618 0676 WSearch - ok
    15:02:01.0712 0676 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
    15:02:01.0743 0676 wuauserv - ok
    15:02:01.0806 0676 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
    15:02:01.0837 0676 WudfPf - ok
    15:02:01.0837 0676 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
    15:02:01.0868 0676 WUDFRd - ok
    15:02:01.0884 0676 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
    15:02:01.0915 0676 wudfsvc - ok
    15:02:01.0930 0676 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    15:02:01.0962 0676 WwanSvc - ok
    15:02:01.0977 0676 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    15:02:02.0180 0676 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
    15:02:02.0180 0676 \Device\Harddisk0\DR0 - detected TDSS File System (1)
    15:02:02.0196 0676 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
    15:02:02.0336 0676 \Device\Harddisk1\DR1 - ok
    15:02:02.0336 0676 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
    15:02:02.0523 0676 \Device\Harddisk2\DR2 - ok
    15:02:02.0523 0676 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk3\DR3
    15:02:03.0069 0676 \Device\Harddisk3\DR3 - ok
    15:02:03.0069 0676 Boot (0x1200) (340d77b4b299b15de4aeddc71bd98243) \Device\Harddisk0\DR0\Partition0
    15:02:03.0069 0676 \Device\Harddisk0\DR0\Partition0 - ok
    15:02:03.0100 0676 Boot (0x1200) (0b77a4731e9214b03b40393561cadf78) \Device\Harddisk0\DR0\Partition1
    15:02:03.0100 0676 \Device\Harddisk0\DR0\Partition1 - ok
    15:02:03.0147 0676 Boot (0x1200) (5c3c71018f858b123a4b9d9a40a3fcd0) \Device\Harddisk1\DR1\Partition0
    15:02:03.0147 0676 \Device\Harddisk1\DR1\Partition0 - ok
    15:02:03.0147 0676 Boot (0x1200) (631f69621fb28148eb2711a4d3a7ac6d) \Device\Harddisk2\DR2\Partition0
    15:02:03.0147 0676 \Device\Harddisk2\DR2\Partition0 - ok
    15:02:03.0163 0676 Boot (0x1200) (dd8321872998b646b1eefa8f126ec27c) \Device\Harddisk2\DR2\Partition1
    15:02:03.0163 0676 \Device\Harddisk2\DR2\Partition1 - ok
    15:02:03.0163 0676 Boot (0x1200) (6372452f237b6fdb4df9440c823a3859) \Device\Harddisk3\DR3\Partition0
    15:02:03.0163 0676 \Device\Harddisk3\DR3\Partition0 - ok
    15:02:03.0163 0676 ============================================================
    15:02:03.0163 0676 Scan finished
    15:02:03.0163 0676 ============================================================
    15:02:03.0178 3636 Detected object count: 1
    15:02:03.0178 3636 Actual detected object count: 1
    15:02:08.0592 3636 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    15:02:08.0592 3636 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
     
  11. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    I want you to re-run the tool and fix both items.
     
  12. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    RK:
    RogueKiller V7.6.4 [07/17/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7600 ) 64 bits version
    Started in : Normal mode
    User: Vincent [Admin rights]
    Mode: Remove -- Date: 07/22/2012 15:32:32

    ¤¤¤ Bad processes: 0 ¤¤¤

    ¤¤¤ Registry Entries: 2 ¤¤¤
    [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver: [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: WDC WD1001FALS-00J7B0 ATA Device +++++
    --- User ---
    [MBR] 97eb5ad0d454d7926d6bcb63f3b827b1
    [BSP] c965afaab793a8107a3ed1784c627274 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: ST3750330AS ATA Device +++++
    --- User ---
    [MBR] 852df5e9ec286f88eaeb41c1a832395c
    [BSP] 1afcd3a018c8d11193bf55da28778d02 : Windows 7 MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 715402 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive2: ST31000528AS ATA Device +++++
    --- User ---
    [MBR] f05533e990d0436e93ee238a0f5ee6d4
    [BSP] 5eb0dd7e0296bddf0cb2cf66da5b79c9 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive3: FLASH Drive 3S_USB20 USB Device +++++
    --- User ---
    [MBR] 10b37fe58f5d2618e64c219f8d8d0feb
    [BSP] 9f4bbb776cd71dbf0ad11bb573a7adc6 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 7635 Mo
    User = LL1 ... OK!
    Error reading LL2 MBR!

    Finished : << RKreport[3].txt >>
    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt


    Rerunning aswMBR now.
     
  13. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    aswMBR still crashing somewhere in the \programfiles scan, and TDSSKiller still picking up one suspicious file.
     
  14. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    I was talking about re-runningTDSSKiller and fixing both items.
     
  15. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    Oh, sorry.

    New TDSS log:
    17:02:07.0580 1440 TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
    17:02:07.0627 1440 ============================================================
    17:02:07.0627 1440 Current date / time: 2012/07/22 17:02:07.0627
    17:02:07.0627 1440 SystemInfo:
    17:02:07.0627 1440
    17:02:07.0627 1440 OS Version: 6.1.7600 ServicePack: 0.0
    17:02:07.0627 1440 Product type: Workstation
    17:02:07.0627 1440 ComputerName: NOISEMACHINE
    17:02:07.0627 1440 UserName: Vincent
    17:02:07.0627 1440 Windows directory: C:\Windows
    17:02:07.0627 1440 System windows directory: C:\Windows
    17:02:07.0627 1440 Running under WOW64
    17:02:07.0627 1440 Processor architecture: Intel x64
    17:02:07.0627 1440 Number of processors: 4
    17:02:07.0627 1440 Page size: 0x1000
    17:02:07.0627 1440 Boot type: Safe boot
    17:02:07.0627 1440 ============================================================
    17:02:08.0485 1440 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
    17:02:08.0485 1440 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    17:02:08.0485 1440 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
    17:02:08.0485 1440 Drive \Device\Harddisk3\DR3 - Size: 0x1DD31E000 (7.46 Gb), SectorSize: 0x200, Cylinders: 0x3CD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    17:02:08.0485 1440 ============================================================
    17:02:08.0485 1440 \Device\Harddisk0\DR0:
    17:02:08.0485 1440 MBR partitions:
    17:02:08.0485 1440 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    17:02:08.0485 1440 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
    17:02:08.0485 1440 \Device\Harddisk1\DR1:
    17:02:08.0485 1440 MBR partitions:
    17:02:08.0485 1440 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x57545000
    17:02:08.0485 1440 \Device\Harddisk2\DR2:
    17:02:08.0485 1440 MBR partitions:
    17:02:08.0485 1440 \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    17:02:08.0485 1440 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
    17:02:08.0485 1440 \Device\Harddisk3\DR3:
    17:02:08.0485 1440 MBR partitions:
    17:02:08.0485 1440 \Device\Harddisk3\DR3\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xEE98B1
    17:02:08.0485 1440 ============================================================
    17:02:08.0501 1440 C: <-> \Device\Harddisk0\DR0\Partition1
    17:02:08.0516 1440 D: <-> \Device\Harddisk1\DR1\Partition0
    17:02:08.0532 1440 E: <-> \Device\Harddisk2\DR2\Partition0
    17:02:08.0532 1440 F: <-> \Device\Harddisk2\DR2\Partition1
    17:02:08.0532 1440 ============================================================
    17:02:08.0532 1440 Initialize success
    17:02:08.0532 1440 ============================================================
    17:02:12.0198 1480 ============================================================
    17:02:12.0198 1480 Scan started
    17:02:12.0198 1480 Mode: Manual; SigCheck; TDLFS;
    17:02:12.0198 1480 ============================================================
    17:02:12.0838 1480 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
    17:02:13.0103 1480 1394ohci - ok
    17:02:13.0118 1480 54556415 - ok
    17:02:13.0150 1480 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
    17:02:13.0165 1480 ACPI - ok
    17:02:13.0181 1480 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
    17:02:13.0212 1480 AcpiPmi - ok
    17:02:13.0274 1480 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    17:02:13.0290 1480 AdobeFlashPlayerUpdateSvc - ok
    17:02:13.0321 1480 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    17:02:13.0337 1480 adp94xx - ok
    17:02:13.0368 1480 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    17:02:13.0384 1480 adpahci - ok
    17:02:13.0399 1480 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    17:02:13.0399 1480 adpu320 - ok
    17:02:13.0430 1480 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    17:02:13.0477 1480 AeLookupSvc - ok
    17:02:13.0524 1480 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
    17:02:13.0555 1480 AFD - ok
    17:02:13.0555 1480 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
    17:02:13.0571 1480 agp440 - ok
    17:02:13.0571 1480 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    17:02:13.0602 1480 ALG - ok
    17:02:13.0618 1480 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
    17:02:13.0633 1480 aliide - ok
    17:02:13.0664 1480 AMD External Events Utility (9c616ba191b80f5cd1a1b9553e107100) C:\Windows\system32\atiesrxx.exe
    17:02:13.0711 1480 AMD External Events Utility - ok
    17:02:13.0711 1480 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
    17:02:13.0711 1480 amdide - ok
    17:02:13.0727 1480 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    17:02:13.0742 1480 AmdK8 - ok
    17:02:14.0132 1480 amdkmdag (5165e83751b8ff40e5e4925996fcc506) C:\Windows\system32\DRIVERS\atikmdag.sys
    17:02:14.0273 1480 amdkmdag - ok
    17:02:14.0366 1480 amdkmdap (86ab3cf484260c4318f3a6e8b035f422) C:\Windows\system32\DRIVERS\atikmpag.sys
    17:02:14.0382 1480 amdkmdap - ok
    17:02:14.0382 1480 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    17:02:14.0413 1480 AmdPPM - ok
    17:02:14.0444 1480 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
    17:02:14.0444 1480 amdsata - ok
    17:02:14.0476 1480 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    17:02:14.0491 1480 amdsbs - ok
    17:02:14.0491 1480 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
    17:02:14.0507 1480 amdxata - ok
    17:02:14.0522 1480 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
    17:02:14.0554 1480 AppID - ok
    17:02:14.0569 1480 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    17:02:14.0600 1480 AppIDSvc - ok
    17:02:14.0616 1480 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
    17:02:14.0647 1480 Appinfo - ok
    17:02:14.0678 1480 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
    17:02:14.0694 1480 AppMgmt - ok
    17:02:14.0710 1480 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    17:02:14.0725 1480 arc - ok
    17:02:14.0725 1480 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    17:02:14.0725 1480 arcsas - ok
    17:02:14.0756 1480 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    17:02:14.0772 1480 AsyncMac - ok
    17:02:14.0788 1480 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
    17:02:14.0788 1480 atapi - ok
    17:02:14.0819 1480 AtiHDAudioService (24464b908e143d2561e9e452fee97309) C:\Windows\system32\drivers\AtihdW76.sys
    17:02:14.0850 1480 AtiHDAudioService - ok
    17:02:14.0881 1480 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    17:02:14.0928 1480 AudioEndpointBuilder - ok
    17:02:14.0928 1480 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    17:02:14.0959 1480 AudioSrv - ok
    17:02:14.0975 1480 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
    17:02:15.0022 1480 AxInstSV - ok
    17:02:15.0053 1480 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    17:02:15.0084 1480 b06bdrv - ok
    17:02:15.0115 1480 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    17:02:15.0131 1480 b57nd60a - ok
    17:02:15.0146 1480 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    17:02:15.0162 1480 BDESVC - ok
    17:02:15.0162 1480 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    17:02:15.0193 1480 Beep - ok
    17:02:15.0240 1480 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
    17:02:15.0271 1480 BFE - ok
    17:02:15.0318 1480 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
    17:02:15.0380 1480 BITS - ok
    17:02:15.0412 1480 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    17:02:15.0427 1480 blbdrive - ok
    17:02:15.0443 1480 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
    17:02:15.0474 1480 bowser - ok
    17:02:15.0474 1480 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    17:02:15.0490 1480 BrFiltLo - ok
    17:02:15.0505 1480 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    17:02:15.0505 1480 BrFiltUp - ok
    17:02:15.0536 1480 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
    17:02:15.0568 1480 Browser - ok
    17:02:15.0583 1480 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    17:02:15.0599 1480 Brserid - ok
    17:02:15.0599 1480 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    17:02:15.0614 1480 BrSerWdm - ok
    17:02:15.0614 1480 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    17:02:15.0646 1480 BrUsbMdm - ok
    17:02:15.0646 1480 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    17:02:15.0661 1480 BrUsbSer - ok
    17:02:15.0661 1480 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    17:02:15.0677 1480 BTHMODEM - ok
    17:02:15.0692 1480 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    17:02:15.0724 1480 bthserv - ok
    17:02:15.0739 1480 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    17:02:15.0770 1480 cdfs - ok
    17:02:15.0786 1480 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
    17:02:15.0802 1480 cdrom - ok
    17:02:15.0833 1480 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    17:02:15.0864 1480 CertPropSvc - ok
    17:02:15.0864 1480 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    17:02:15.0880 1480 circlass - ok
    17:02:15.0895 1480 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    17:02:15.0911 1480 CLFS - ok
    17:02:15.0942 1480 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    17:02:15.0958 1480 clr_optimization_v2.0.50727_32 - ok
    17:02:15.0989 1480 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    17:02:15.0989 1480 clr_optimization_v2.0.50727_64 - ok
    17:02:16.0051 1480 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    17:02:16.0082 1480 clr_optimization_v4.0.30319_32 - ok
    17:02:16.0098 1480 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    17:02:16.0098 1480 clr_optimization_v4.0.30319_64 - ok
    17:02:16.0114 1480 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    17:02:16.0114 1480 CmBatt - ok
    17:02:16.0129 1480 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
    17:02:16.0129 1480 cmdide - ok
    17:02:16.0160 1480 CNG (ca7720b73446fddec5c69519c1174c98) C:\Windows\system32\Drivers\cng.sys
    17:02:16.0207 1480 CNG - ok
    17:02:16.0223 1480 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    17:02:16.0238 1480 Compbatt - ok
    17:02:16.0238 1480 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
    17:02:16.0254 1480 CompositeBus - ok
    17:02:16.0254 1480 COMSysApp - ok
    17:02:16.0270 1480 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    17:02:16.0270 1480 crcdisk - ok
    17:02:16.0301 1480 CryptSvc (f02786b66375292e58c8777082d4396d) C:\Windows\system32\cryptsvc.dll
    17:02:16.0332 1480 CryptSvc - ok
    17:02:16.0363 1480 CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
    17:02:16.0379 1480 CSC - ok
    17:02:16.0410 1480 CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
    17:02:16.0441 1480 CscService - ok
    17:02:16.0488 1480 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    17:02:16.0535 1480 DcomLaunch - ok
    17:02:16.0566 1480 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    17:02:16.0597 1480 defragsvc - ok
    17:02:16.0628 1480 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
    17:02:16.0644 1480 DfsC - ok
    17:02:16.0675 1480 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
    17:02:16.0722 1480 Dhcp - ok
    17:02:16.0738 1480 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    17:02:16.0784 1480 discache - ok
    17:02:16.0800 1480 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    17:02:16.0800 1480 Disk - ok
    17:02:16.0831 1480 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
    17:02:16.0847 1480 Dnscache - ok
    17:02:16.0862 1480 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
    17:02:16.0894 1480 dot3svc - ok
    17:02:16.0909 1480 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
    17:02:16.0940 1480 DPS - ok
    17:02:16.0956 1480 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    17:02:16.0972 1480 drmkaud - ok
    17:02:17.0018 1480 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
    17:02:17.0034 1480 DXGKrnl - ok
    17:02:17.0050 1480 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    17:02:17.0081 1480 EapHost - ok
    17:02:17.0206 1480 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    17:02:17.0268 1480 ebdrv - ok
    17:02:17.0330 1480 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
    17:02:17.0362 1480 EFS - ok
    17:02:17.0408 1480 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
    17:02:17.0440 1480 ehRecvr - ok
    17:02:17.0471 1480 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    17:02:17.0486 1480 ehSched - ok
    17:02:17.0502 1480 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    17:02:17.0518 1480 elxstor - ok
    17:02:17.0533 1480 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
    17:02:17.0549 1480 ErrDev - ok
    17:02:17.0596 1480 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    17:02:17.0611 1480 EventSystem - ok
    17:02:17.0627 1480 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    17:02:17.0658 1480 exfat - ok
    17:02:17.0674 1480 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    17:02:17.0689 1480 fastfat - ok
    17:02:17.0736 1480 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
    17:02:17.0752 1480 Fax - ok
    17:02:17.0767 1480 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    17:02:17.0783 1480 fdc - ok
    17:02:17.0798 1480 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    17:02:17.0814 1480 fdPHost - ok
    17:02:17.0814 1480 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    17:02:17.0861 1480 FDResPub - ok
    17:02:17.0861 1480 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    17:02:17.0861 1480 FileInfo - ok
    17:02:17.0876 1480 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    17:02:17.0908 1480 Filetrace - ok
    17:02:17.0908 1480 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    17:02:17.0923 1480 flpydisk - ok
    17:02:17.0939 1480 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
    17:02:17.0954 1480 FltMgr - ok
    17:02:18.0017 1480 FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
    17:02:18.0048 1480 FontCache - ok
    17:02:18.0079 1480 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    17:02:18.0095 1480 FontCache3.0.0.0 - ok
    17:02:18.0095 1480 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    17:02:18.0110 1480 FsDepends - ok
    17:02:18.0126 1480 Fs_Rec (d3e3f93d67821a2db2b3d9fac2dc2064) C:\Windows\system32\drivers\Fs_Rec.sys
    17:02:18.0126 1480 Fs_Rec - ok
    17:02:18.0173 1480 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
    17:02:18.0188 1480 fvevol - ok
    17:02:18.0188 1480 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    17:02:18.0204 1480 gagp30kx - ok
    17:02:18.0251 1480 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
    17:02:18.0282 1480 gpsvc - ok
    17:02:18.0298 1480 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    17:02:18.0313 1480 hcw85cir - ok
    17:02:18.0360 1480 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
    17:02:18.0376 1480 HdAudAddService - ok
    17:02:18.0391 1480 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    17:02:18.0407 1480 HDAudBus - ok
    17:02:18.0469 1480 HDDHealth (354f7ac7ae454a1daf85bf7c0ffefd07) C:\Program Files (x86)\HDD Health\HDDHealthService.exe
    17:02:18.0485 1480 HDDHealth - ok
    17:02:18.0485 1480 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    17:02:18.0500 1480 HidBatt - ok
    17:02:18.0500 1480 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    17:02:18.0516 1480 HidBth - ok
    17:02:18.0516 1480 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    17:02:18.0532 1480 HidIr - ok
    17:02:18.0547 1480 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
    17:02:18.0578 1480 hidserv - ok
    17:02:18.0594 1480 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
    17:02:18.0610 1480 HidUsb - ok
    17:02:18.0625 1480 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
    17:02:18.0656 1480 hkmsvc - ok
    17:02:18.0672 1480 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
    17:02:18.0688 1480 HomeGroupListener - ok
    17:02:18.0719 1480 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
    17:02:18.0734 1480 HomeGroupProvider - ok
    17:02:18.0750 1480 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
    17:02:18.0750 1480 HpSAMD - ok
    17:02:18.0797 1480 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
    17:02:18.0828 1480 HTTP - ok
    17:02:18.0828 1480 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
    17:02:18.0844 1480 hwpolicy - ok
    17:02:18.0859 1480 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    17:02:18.0859 1480 i8042prt - ok
    17:02:18.0890 1480 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
    17:02:18.0890 1480 iaStorV - ok
    17:02:18.0968 1480 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    17:02:18.0984 1480 idsvc - ok
    17:02:18.0984 1480 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    17:02:18.0984 1480 iirsp - ok
    17:02:19.0031 1480 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
    17:02:19.0078 1480 IKEEXT - ok
    17:02:19.0093 1480 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
    17:02:19.0093 1480 intelide - ok
    17:02:19.0109 1480 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    17:02:19.0124 1480 intelppm - ok
    17:02:19.0140 1480 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    17:02:19.0171 1480 IPBusEnum - ok
    17:02:19.0187 1480 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    17:02:19.0202 1480 IpFilterDriver - ok
    17:02:19.0234 1480 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
    17:02:19.0280 1480 iphlpsvc - ok
    17:02:19.0280 1480 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
    17:02:19.0296 1480 IPMIDRV - ok
    17:02:19.0312 1480 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    17:02:19.0343 1480 IPNAT - ok
    17:02:19.0343 1480 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    17:02:19.0358 1480 IRENUM - ok
    17:02:19.0358 1480 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
    17:02:19.0358 1480 isapnp - ok
    17:02:19.0390 1480 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
    17:02:19.0390 1480 iScsiPrt - ok
    17:02:19.0421 1480 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    17:02:19.0421 1480 kbdclass - ok
    17:02:19.0436 1480 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
    17:02:19.0452 1480 kbdhid - ok
    17:02:19.0468 1480 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    17:02:19.0483 1480 KeyIso - ok
    17:02:19.0499 1480 KSecDD (4f4b5fde429416877de7143044582eb5) C:\Windows\system32\Drivers\ksecdd.sys
    17:02:19.0499 1480 KSecDD - ok
    17:02:19.0514 1480 KSecPkg (6f40465a44ecdc1731befafec5bdd03c) C:\Windows\system32\Drivers\ksecpkg.sys
    17:02:19.0514 1480 KSecPkg - ok
    17:02:19.0530 1480 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    17:02:19.0561 1480 ksthunk - ok
    17:02:19.0592 1480 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    17:02:19.0624 1480 KtmRm - ok
    17:02:19.0639 1480 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\system32\srvsvc.dll
    17:02:19.0670 1480 LanmanServer - ok
    17:02:19.0686 1480 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
    17:02:19.0717 1480 LanmanWorkstation - ok
    17:02:19.0733 1480 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    17:02:19.0764 1480 lltdio - ok
    17:02:19.0780 1480 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    17:02:19.0811 1480 lltdsvc - ok
    17:02:19.0826 1480 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    17:02:19.0842 1480 lmhosts - ok
    17:02:19.0858 1480 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    17:02:19.0858 1480 LSI_FC - ok
    17:02:19.0873 1480 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    17:02:19.0873 1480 LSI_SAS - ok
    17:02:19.0889 1480 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    17:02:19.0889 1480 LSI_SAS2 - ok
    17:02:19.0904 1480 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    17:02:19.0904 1480 LSI_SCSI - ok
    17:02:19.0920 1480 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    17:02:19.0951 1480 luafv - ok
    17:02:19.0982 1480 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
    17:02:19.0982 1480 MBAMProtector - ok
    17:02:20.0045 1480 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    17:02:20.0076 1480 MBAMService - ok
    17:02:20.0092 1480 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
    17:02:20.0107 1480 Mcx2Svc - ok
    17:02:20.0123 1480 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    17:02:20.0123 1480 megasas - ok
    17:02:20.0138 1480 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    17:02:20.0154 1480 MegaSR - ok
    17:02:20.0185 1480 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    17:02:20.0216 1480 MMCSS - ok
    17:02:20.0216 1480 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    17:02:20.0248 1480 Modem - ok
    17:02:20.0248 1480 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    17:02:20.0263 1480 monitor - ok
    17:02:20.0279 1480 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    17:02:20.0279 1480 mouclass - ok
    17:02:20.0294 1480 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    17:02:20.0294 1480 mouhid - ok
    17:02:20.0310 1480 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
    17:02:20.0310 1480 mountmgr - ok
    17:02:20.0341 1480 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    17:02:20.0341 1480 MozillaMaintenance - ok
    17:02:20.0388 1480 MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
    17:02:20.0388 1480 MpFilter - ok
    17:02:20.0404 1480 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
    17:02:20.0404 1480 mpio - ok
    17:02:20.0419 1480 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    17:02:20.0435 1480 mpsdrv - ok
    17:02:20.0482 1480 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
    17:02:20.0528 1480 MpsSvc - ok
    17:02:20.0544 1480 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
    17:02:20.0560 1480 MRxDAV - ok
    17:02:20.0575 1480 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
    17:02:20.0606 1480 mrxsmb - ok
    17:02:20.0622 1480 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    17:02:20.0638 1480 mrxsmb10 - ok
    17:02:20.0638 1480 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    17:02:20.0669 1480 mrxsmb20 - ok
     
  16. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    17:02:20.0669 1480 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
    17:02:20.0669 1480 msahci - ok
    17:02:20.0684 1480 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
    17:02:20.0684 1480 msdsm - ok
    17:02:20.0716 1480 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    17:02:20.0731 1480 MSDTC - ok
    17:02:20.0747 1480 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    17:02:20.0762 1480 Msfs - ok
    17:02:20.0778 1480 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    17:02:20.0809 1480 mshidkmdf - ok
    17:02:20.0825 1480 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
    17:02:20.0825 1480 msisadrv - ok
    17:02:20.0856 1480 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    17:02:20.0872 1480 MSiSCSI - ok
    17:02:20.0887 1480 msiserver - ok
    17:02:20.0903 1480 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    17:02:20.0918 1480 MSKSSRV - ok
    17:02:20.0965 1480 MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
    17:02:20.0965 1480 MsMpSvc - ok
    17:02:20.0981 1480 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    17:02:20.0996 1480 MSPCLOCK - ok
    17:02:20.0996 1480 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    17:02:21.0028 1480 MSPQM - ok
    17:02:21.0043 1480 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
    17:02:21.0059 1480 MsRPC - ok
    17:02:21.0059 1480 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
    17:02:21.0074 1480 mssmbios - ok
    17:02:21.0074 1480 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    17:02:21.0106 1480 MSTEE - ok
    17:02:21.0121 1480 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    17:02:21.0121 1480 MTConfig - ok
    17:02:21.0137 1480 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    17:02:21.0137 1480 Mup - ok
    17:02:21.0168 1480 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
    17:02:21.0199 1480 napagent - ok
    17:02:21.0230 1480 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    17:02:21.0246 1480 NativeWifiP - ok
    17:02:21.0293 1480 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
    17:02:21.0308 1480 NDIS - ok
    17:02:21.0324 1480 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    17:02:21.0340 1480 NdisCap - ok
    17:02:21.0355 1480 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    17:02:21.0386 1480 NdisTapi - ok
    17:02:21.0386 1480 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
    17:02:21.0418 1480 Ndisuio - ok
    17:02:21.0418 1480 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
    17:02:21.0449 1480 NdisWan - ok
    17:02:21.0449 1480 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
    17:02:21.0480 1480 NDProxy - ok
    17:02:21.0480 1480 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    17:02:21.0511 1480 NetBIOS - ok
    17:02:21.0511 1480 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
    17:02:21.0542 1480 NetBT - ok
    17:02:21.0558 1480 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    17:02:21.0558 1480 Netlogon - ok
    17:02:21.0589 1480 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    17:02:21.0636 1480 Netman - ok
    17:02:21.0652 1480 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    17:02:21.0683 1480 netprofm - ok
    17:02:21.0714 1480 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    17:02:21.0730 1480 NetTcpPortSharing - ok
    17:02:21.0730 1480 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    17:02:21.0745 1480 nfrd960 - ok
    17:02:21.0761 1480 NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
    17:02:21.0776 1480 NisDrv - ok
    17:02:21.0823 1480 NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
    17:02:21.0823 1480 NisSrv - ok
    17:02:21.0854 1480 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
    17:02:21.0886 1480 NlaSvc - ok
    17:02:21.0886 1480 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    17:02:21.0917 1480 Npfs - ok
    17:02:21.0932 1480 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    17:02:21.0948 1480 nsi - ok
    17:02:21.0948 1480 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    17:02:21.0979 1480 nsiproxy - ok
    17:02:22.0042 1480 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
    17:02:22.0073 1480 Ntfs - ok
    17:02:22.0151 1480 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    17:02:22.0166 1480 Null - ok
    17:02:22.0182 1480 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
    17:02:22.0198 1480 nvraid - ok
    17:02:22.0213 1480 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
    17:02:22.0213 1480 nvstor - ok
    17:02:22.0229 1480 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
    17:02:22.0244 1480 nv_agp - ok
    17:02:22.0244 1480 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
    17:02:22.0244 1480 ohci1394 - ok
    17:02:22.0276 1480 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    17:02:22.0291 1480 p2pimsvc - ok
    17:02:22.0322 1480 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    17:02:22.0338 1480 p2psvc - ok
    17:02:22.0338 1480 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    17:02:22.0354 1480 Parport - ok
    17:02:22.0369 1480 partmgr (90061b1acfe8ccaa5345750ffe08d8b8) C:\Windows\system32\drivers\partmgr.sys
    17:02:22.0369 1480 partmgr - ok
    17:02:22.0385 1480 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    17:02:22.0400 1480 PcaSvc - ok
    17:02:22.0416 1480 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
    17:02:22.0432 1480 pci - ok
    17:02:22.0432 1480 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
    17:02:22.0447 1480 pciide - ok
    17:02:22.0447 1480 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    17:02:22.0463 1480 pcmcia - ok
    17:02:22.0463 1480 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    17:02:22.0478 1480 pcw - ok
    17:02:22.0494 1480 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    17:02:22.0525 1480 PEAUTH - ok
    17:02:22.0603 1480 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
    17:02:22.0634 1480 PeerDistSvc - ok
    17:02:22.0681 1480 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    17:02:22.0697 1480 PerfHost - ok
    17:02:22.0790 1480 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
    17:02:22.0837 1480 pla - ok
    17:02:22.0884 1480 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
    17:02:22.0915 1480 PlugPlay - ok
    17:02:22.0915 1480 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    17:02:22.0931 1480 PNRPAutoReg - ok
    17:02:22.0962 1480 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    17:02:22.0962 1480 PNRPsvc - ok
    17:02:23.0024 1480 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
    17:02:23.0056 1480 PolicyAgent - ok
    17:02:23.0071 1480 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    17:02:23.0102 1480 Power - ok
    17:02:23.0134 1480 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
    17:02:23.0165 1480 PptpMiniport - ok
    17:02:23.0165 1480 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    17:02:23.0180 1480 Processor - ok
    17:02:23.0212 1480 ProfSvc (97293447431311c06703368ad0f6c4be) C:\Windows\system32\profsvc.dll
    17:02:23.0227 1480 ProfSvc - ok
    17:02:23.0243 1480 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    17:02:23.0243 1480 ProtectedStorage - ok
    17:02:23.0258 1480 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
    17:02:23.0290 1480 Psched - ok
    17:02:23.0352 1480 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    17:02:23.0368 1480 ql2300 - ok
    17:02:23.0430 1480 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    17:02:23.0430 1480 ql40xx - ok
    17:02:23.0446 1480 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    17:02:23.0461 1480 QWAVE - ok
    17:02:23.0461 1480 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    17:02:23.0477 1480 QWAVEdrv - ok
    17:02:23.0492 1480 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    17:02:23.0508 1480 RasAcd - ok
    17:02:23.0539 1480 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    17:02:23.0555 1480 RasAgileVpn - ok
    17:02:23.0570 1480 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    17:02:23.0602 1480 RasAuto - ok
    17:02:23.0602 1480 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
    17:02:23.0633 1480 Rasl2tp - ok
    17:02:23.0648 1480 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
    17:02:23.0695 1480 RasMan - ok
    17:02:23.0711 1480 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    17:02:23.0742 1480 RasPppoe - ok
    17:02:23.0742 1480 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    17:02:23.0789 1480 RasSstp - ok
    17:02:23.0789 1480 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
    17:02:23.0820 1480 rdbss - ok
    17:02:23.0820 1480 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    17:02:23.0851 1480 rdpbus - ok
    17:02:23.0851 1480 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    17:02:23.0867 1480 RDPCDD - ok
    17:02:23.0882 1480 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
    17:02:23.0914 1480 RDPDR - ok
    17:02:23.0929 1480 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    17:02:23.0945 1480 RDPENCDD - ok
    17:02:23.0960 1480 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    17:02:23.0992 1480 RDPREFMP - ok
    17:02:24.0023 1480 RDPWD (447de7e3dea39d422c1504f245b668b1) C:\Windows\system32\drivers\RDPWD.sys
    17:02:24.0038 1480 RDPWD - ok
    17:02:24.0054 1480 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
    17:02:24.0070 1480 rdyboost - ok
    17:02:24.0085 1480 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    17:02:24.0132 1480 RemoteAccess - ok
    17:02:24.0148 1480 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    17:02:24.0179 1480 RemoteRegistry - ok
    17:02:24.0194 1480 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    17:02:24.0226 1480 RpcEptMapper - ok
    17:02:24.0241 1480 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    17:02:24.0257 1480 RpcLocator - ok
    17:02:24.0288 1480 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    17:02:24.0304 1480 RpcSs - ok
    17:02:24.0319 1480 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    17:02:24.0335 1480 rspndr - ok
    17:02:24.0366 1480 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
    17:02:24.0366 1480 RTL8167 - ok
    17:02:24.0413 1480 RTL8187B (4a06585c8673f4458e9fbbc9dddb4d28) C:\Windows\system32\DRIVERS\wg111v3.sys
    17:02:24.0428 1480 RTL8187B - ok
    17:02:24.0444 1480 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
    17:02:24.0460 1480 s3cap - ok
    17:02:24.0475 1480 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    17:02:24.0491 1480 SamSs - ok
    17:02:24.0491 1480 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
    17:02:24.0506 1480 sbp2port - ok
    17:02:24.0522 1480 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    17:02:24.0553 1480 SCardSvr - ok
    17:02:24.0553 1480 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
    17:02:24.0600 1480 scfilter - ok
    17:02:24.0662 1480 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
    17:02:24.0694 1480 Schedule - ok
    17:02:24.0709 1480 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    17:02:24.0725 1480 SCPolicySvc - ok
    17:02:24.0756 1480 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
    17:02:24.0772 1480 SDRSVC - ok
    17:02:24.0803 1480 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    17:02:24.0834 1480 secdrv - ok
    17:02:24.0834 1480 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
    17:02:24.0865 1480 seclogon - ok
    17:02:24.0865 1480 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
    17:02:24.0896 1480 SENS - ok
    17:02:24.0912 1480 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    17:02:24.0928 1480 SensrSvc - ok
    17:02:24.0928 1480 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    17:02:24.0943 1480 Serenum - ok
    17:02:24.0959 1480 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    17:02:24.0959 1480 Serial - ok
    17:02:24.0974 1480 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    17:02:24.0990 1480 sermouse - ok
    17:02:24.0990 1480 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
    17:02:25.0021 1480 SessionEnv - ok
    17:02:25.0021 1480 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
    17:02:25.0037 1480 sffdisk - ok
    17:02:25.0037 1480 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
    17:02:25.0052 1480 sffp_mmc - ok
    17:02:25.0052 1480 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
    17:02:25.0068 1480 sffp_sd - ok
    17:02:25.0068 1480 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    17:02:25.0068 1480 sfloppy - ok
    17:02:25.0099 1480 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    17:02:25.0146 1480 SharedAccess - ok
    17:02:25.0162 1480 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
    17:02:25.0193 1480 ShellHWDetection - ok
    17:02:25.0193 1480 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    17:02:25.0208 1480 SiSRaid2 - ok
    17:02:25.0208 1480 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    17:02:25.0208 1480 SiSRaid4 - ok
    17:02:25.0255 1480 SkypeUpdate (f07af60b152221472fbdb2fecec4896d) C:\Program Files (x86)\Skype\Updater\Updater.exe
    17:02:25.0255 1480 SkypeUpdate - ok
    17:02:25.0271 1480 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    17:02:25.0286 1480 Smb - ok
    17:02:25.0318 1480 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    17:02:25.0333 1480 SNMPTRAP - ok
    17:02:25.0333 1480 SophosVirusRemovalTool - ok
    17:02:25.0333 1480 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    17:02:25.0349 1480 spldr - ok
    17:02:25.0380 1480 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
    17:02:25.0411 1480 Spooler - ok
    17:02:25.0536 1480 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
    17:02:25.0598 1480 sppsvc - ok
    17:02:25.0661 1480 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    17:02:25.0692 1480 sppuinotify - ok
    17:02:25.0739 1480 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
    17:02:25.0754 1480 srv - ok
    17:02:25.0786 1480 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
    17:02:25.0786 1480 srv2 - ok
    17:02:25.0801 1480 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
    17:02:25.0832 1480 srvnet - ok
    17:02:25.0848 1480 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    17:02:25.0879 1480 SSDPSRV - ok
    17:02:25.0895 1480 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    17:02:25.0910 1480 SstpSvc - ok
    17:02:25.0926 1480 Steam Client Service - ok
    17:02:25.0957 1480 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    17:02:25.0957 1480 stexstor - ok
    17:02:25.0988 1480 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
    17:02:26.0020 1480 stisvc - ok
    17:02:26.0035 1480 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
    17:02:26.0051 1480 storflt - ok
    17:02:26.0066 1480 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
    17:02:26.0066 1480 storvsc - ok
    17:02:26.0082 1480 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
    17:02:26.0082 1480 swenum - ok
    17:02:26.0113 1480 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    17:02:26.0160 1480 swprv - ok
    17:02:26.0222 1480 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
    17:02:26.0285 1480 SysMain - ok
    17:02:26.0347 1480 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
    17:02:26.0363 1480 TabletInputService - ok
    17:02:26.0394 1480 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
    17:02:26.0425 1480 TapiSrv - ok
    17:02:26.0441 1480 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    17:02:26.0456 1480 TBS - ok
    17:02:26.0550 1480 Tcpip (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\drivers\tcpip.sys
    17:02:26.0597 1480 Tcpip - ok
    17:02:26.0690 1480 TCPIP6 (624c5b3aa4c99b3184bb922d9ece3ff0) C:\Windows\system32\DRIVERS\tcpip.sys
    17:02:26.0722 1480 TCPIP6 - ok
    17:02:26.0753 1480 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
    17:02:26.0768 1480 tcpipreg - ok
    17:02:26.0800 1480 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    17:02:26.0815 1480 TDPIPE - ok
    17:02:26.0831 1480 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
    17:02:26.0846 1480 TDTCP - ok
    17:02:26.0862 1480 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
    17:02:26.0893 1480 tdx - ok
    17:02:26.0893 1480 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
    17:02:26.0893 1480 TermDD - ok
    17:02:26.0940 1480 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
    17:02:26.0987 1480 TermService - ok
    17:02:26.0987 1480 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    17:02:27.0018 1480 Themes - ok
    17:02:27.0034 1480 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    17:02:27.0049 1480 THREADORDER - ok
    17:02:27.0065 1480 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    17:02:27.0096 1480 TrkWks - ok
    17:02:27.0127 1480 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
    17:02:27.0143 1480 TrustedInstaller - ok
    17:02:27.0158 1480 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
    17:02:27.0190 1480 tssecsrv - ok
    17:02:27.0205 1480 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
    17:02:27.0236 1480 tunnel - ok
    17:02:27.0236 1480 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    17:02:27.0236 1480 uagp35 - ok
    17:02:27.0252 1480 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
    17:02:27.0283 1480 udfs - ok
    17:02:27.0299 1480 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    17:02:27.0299 1480 UI0Detect - ok
    17:02:27.0314 1480 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
    17:02:27.0314 1480 uliagpkx - ok
    17:02:27.0330 1480 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
    17:02:27.0346 1480 umbus - ok
    17:02:27.0346 1480 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    17:02:27.0361 1480 UmPass - ok
    17:02:27.0392 1480 UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
    17:02:27.0408 1480 UmRdpService - ok
    17:02:27.0424 1480 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    17:02:27.0455 1480 upnphost - ok
    17:02:27.0455 1480 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
    17:02:27.0486 1480 usbccgp - ok
    17:02:27.0486 1480 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    17:02:27.0502 1480 usbcir - ok
    17:02:27.0502 1480 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
    17:02:27.0502 1480 usbehci - ok
    17:02:27.0517 1480 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
    17:02:27.0533 1480 usbhub - ok
    17:02:27.0548 1480 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
    17:02:27.0564 1480 usbohci - ok
    17:02:27.0564 1480 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    17:02:27.0580 1480 usbprint - ok
    17:02:27.0580 1480 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    17:02:27.0580 1480 USBSTOR - ok
    17:02:27.0595 1480 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
    17:02:27.0595 1480 usbuhci - ok
    17:02:27.0611 1480 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    17:02:27.0642 1480 UxSms - ok
    17:02:27.0658 1480 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
    17:02:27.0658 1480 VaultSvc - ok
    17:02:27.0673 1480 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
    17:02:27.0673 1480 vdrvroot - ok
    17:02:27.0720 1480 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
    17:02:27.0736 1480 vds - ok
    17:02:27.0736 1480 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    17:02:27.0751 1480 vga - ok
    17:02:27.0751 1480 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    17:02:27.0782 1480 VgaSave - ok
    17:02:27.0782 1480 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
    17:02:27.0798 1480 vhdmp - ok
    17:02:27.0798 1480 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
    17:02:27.0814 1480 viaide - ok
    17:02:27.0829 1480 vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
    17:02:27.0829 1480 vmbus - ok
    17:02:27.0845 1480 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
    17:02:27.0845 1480 VMBusHID - ok
    17:02:27.0860 1480 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
    17:02:27.0876 1480 volmgr - ok
    17:02:27.0892 1480 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
    17:02:27.0907 1480 volmgrx - ok
    17:02:27.0923 1480 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
    17:02:27.0923 1480 volsnap - ok
    17:02:27.0938 1480 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    17:02:27.0954 1480 vsmraid - ok
    17:02:28.0016 1480 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
    17:02:28.0048 1480 VSS - ok
    17:02:28.0110 1480 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
    17:02:28.0126 1480 vwifibus - ok
    17:02:28.0126 1480 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    17:02:28.0141 1480 vwififlt - ok
    17:02:28.0172 1480 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    17:02:28.0204 1480 W32Time - ok
    17:02:28.0204 1480 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    17:02:28.0219 1480 WacomPen - ok
    17:02:28.0250 1480 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    17:02:28.0282 1480 WANARP - ok
    17:02:28.0282 1480 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    17:02:28.0313 1480 Wanarpv6 - ok
    17:02:28.0391 1480 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    17:02:28.0422 1480 WatAdminSvc - ok
    17:02:28.0484 1480 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
    17:02:28.0531 1480 wbengine - ok
    17:02:28.0562 1480 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    17:02:28.0578 1480 WbioSrvc - ok
    17:02:28.0609 1480 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
    17:02:28.0640 1480 wcncsvc - ok
    17:02:28.0656 1480 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    17:02:28.0656 1480 WcsPlugInService - ok
    17:02:28.0672 1480 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    17:02:28.0687 1480 Wd - ok
    17:02:28.0718 1480 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    17:02:28.0734 1480 Wdf01000 - ok
    17:02:28.0750 1480 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    17:02:28.0765 1480 WdiServiceHost - ok
    17:02:28.0765 1480 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    17:02:28.0781 1480 WdiSystemHost - ok
    17:02:28.0796 1480 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
    17:02:28.0828 1480 WebClient - ok
    17:02:28.0843 1480 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    17:02:28.0874 1480 Wecsvc - ok
    17:02:28.0874 1480 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    17:02:28.0906 1480 wercplsupport - ok
    17:02:28.0906 1480 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    17:02:28.0937 1480 WerSvc - ok
    17:02:28.0952 1480 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    17:02:28.0984 1480 WfpLwf - ok
    17:02:28.0984 1480 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    17:02:28.0999 1480 WIMMount - ok
    17:02:29.0015 1480 WinDefend - ok
    17:02:29.0015 1480 WinHttpAutoProxySvc - ok
    17:02:29.0062 1480 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    17:02:29.0093 1480 Winmgmt - ok
    17:02:29.0171 1480 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
    17:02:29.0249 1480 WinRM - ok
    17:02:29.0342 1480 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    17:02:29.0374 1480 Wlansvc - ok
    17:02:29.0374 1480 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
    17:02:29.0389 1480 WmiAcpi - ok
    17:02:29.0420 1480 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    17:02:29.0420 1480 wmiApSrv - ok
    17:02:29.0436 1480 WMPNetworkSvc - ok
    17:02:29.0452 1480 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    17:02:29.0467 1480 WPCSvc - ok
    17:02:29.0483 1480 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
    17:02:29.0498 1480 WPDBusEnum - ok
    17:02:29.0498 1480 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    17:02:29.0530 1480 ws2ifsl - ok
    17:02:29.0545 1480 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\System32\wscsvc.dll
    17:02:29.0561 1480 wscsvc - ok
    17:02:29.0561 1480 WSearch - ok
    17:02:29.0654 1480 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
    17:02:29.0701 1480 wuauserv - ok
    17:02:29.0764 1480 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
    17:02:29.0795 1480 WudfPf - ok
    17:02:29.0826 1480 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
    17:02:29.0857 1480 WUDFRd - ok
    17:02:29.0873 1480 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
    17:02:29.0888 1480 wudfsvc - ok
    17:02:29.0920 1480 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    17:02:29.0935 1480 WwanSvc - ok
    17:02:29.0966 1480 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    17:02:30.0154 1480 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
    17:02:30.0154 1480 \Device\Harddisk0\DR0 - detected TDSS File System (1)
    17:02:30.0154 1480 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
    17:02:30.0263 1480 \Device\Harddisk1\DR1 - ok
    17:02:30.0278 1480 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
    17:02:30.0481 1480 \Device\Harddisk2\DR2 - ok
    17:02:30.0497 1480 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk3\DR3
    17:02:31.0043 1480 \Device\Harddisk3\DR3 - ok
    17:02:31.0043 1480 Boot (0x1200) (340d77b4b299b15de4aeddc71bd98243) \Device\Harddisk0\DR0\Partition0
    17:02:31.0043 1480 \Device\Harddisk0\DR0\Partition0 - ok
    17:02:31.0058 1480 Boot (0x1200) (0b77a4731e9214b03b40393561cadf78) \Device\Harddisk0\DR0\Partition1
    17:02:31.0058 1480 \Device\Harddisk0\DR0\Partition1 - ok
    17:02:31.0058 1480 Boot (0x1200) (5c3c71018f858b123a4b9d9a40a3fcd0) \Device\Harddisk1\DR1\Partition0
    17:02:31.0058 1480 \Device\Harddisk1\DR1\Partition0 - ok
    17:02:31.0058 1480 Boot (0x1200) (631f69621fb28148eb2711a4d3a7ac6d) \Device\Harddisk2\DR2\Partition0
    17:02:31.0058 1480 \Device\Harddisk2\DR2\Partition0 - ok
    17:02:31.0058 1480 Boot (0x1200) (dd8321872998b646b1eefa8f126ec27c) \Device\Harddisk2\DR2\Partition1
    17:02:31.0058 1480 \Device\Harddisk2\DR2\Partition1 - ok
    17:02:31.0074 1480 Boot (0x1200) (6372452f237b6fdb4df9440c823a3859) \Device\Harddisk3\DR3\Partition0
    17:02:31.0074 1480 \Device\Harddisk3\DR3\Partition0 - ok
    17:02:31.0074 1480 ============================================================
    17:02:31.0074 1480 Scan finished
    17:02:31.0074 1480 ============================================================
    17:02:31.0074 1472 Detected object count: 1
    17:02:31.0074 1472 Actual detected object count: 1
    17:02:41.0323 1472 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
    17:02:41.0323 1472 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
    17:02:41.0323 1472 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
    17:02:41.0323 1472 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
    17:02:41.0323 1472 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
    17:02:41.0339 1472 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
    17:02:41.0355 1472 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
    17:02:41.0386 1472 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
    17:02:41.0386 1472 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
    17:02:41.0386 1472 \Device\Harddisk0\DR0\TDLFS - deleted
    17:02:41.0386 1472 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
     
  17. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Good :)

    See if aswMBR will run now.
    If so, post its log.

    Next....

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  18. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    So far, no luck with aswMBR; if I can't get aswMBR to work, should I run CF anyway?
     
  19. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Yes, go ahead with Combofix.
     
  20. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    I didn't get a combofix.txt log; it just came out as "log". Posting anyway!
    aswMBR didn't work, though.


    Combofix:
    ComboFix 12-07-21.01 - Vincent 07/22/2012 17:57:46.1.4 - x64
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6142.4584 [GMT -5:00]
    Running from: c:\users\Vincent\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
    .
    .
    2012-07-22 18:19 . 2012-06-29 08:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32EFCE45-5C52-4AC8-8974-4399B2874934}\mpengine.dll
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----r- c:\program files (x86)\Skype
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----w- c:\programdata\Skype
    2012-07-22 08:37 . 2012-07-22 08:37 -------- d-----w- c:\program files (x86)\HDD Health
    2012-07-22 08:29 . 2012-07-22 08:29 -------- d-----w- c:\programdata\McAfee
    2012-07-22 08:29 . 2012-07-22 08:29 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-22 08:29 . 2012-07-22 08:29 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-22 08:28 . 2012-07-22 08:28 -------- d-----w- c:\windows\SysWow64\Macromed
    2012-07-22 08:28 . 2012-07-22 08:28 -------- d-----w- c:\windows\system32\Macromed
    2012-07-22 05:17 . 2012-07-22 05:17 -------- d-----w- c:\programdata\Malwarebytes
    2012-07-22 05:17 . 2012-07-22 05:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-07-22 05:17 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-22 04:18 . 2012-07-22 04:19 -------- d-----w- c:\program files\WinRAR
    2012-07-22 04:03 . 2008-03-05 20:56 4910088 ----a-w- c:\windows\system32\D3DX9_37.dll
    2012-07-22 02:39 . 2012-07-22 02:39 -------- d-----w- c:\programdata\ATI
    2012-07-22 02:39 . 2012-07-22 02:39 -------- d-----w- c:\program files (x86)\AMD APP
    2012-07-22 02:35 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
    2012-07-22 02:35 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
    2012-07-22 02:35 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\programdata\AMD
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\AMD AVT
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files\Common Files\ATI Technologies
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\ATI Technologies
    2012-07-22 02:29 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
    2012-07-22 02:29 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
    2012-07-22 02:28 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2012-07-22 02:28 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
    2012-07-22 02:27 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll
    2012-07-22 02:26 . 2012-07-22 02:26 -------- d-----w- c:\program files (x86)\Microsoft.NET
    2012-07-22 02:26 . 2012-07-22 02:26 1831424 ----a-w- c:\windows\SysWow64\atiumdmv.dll
    2012-07-22 02:26 . 2012-07-22 02:26 1120768 ----a-w- c:\windows\system32\atiumd6v.dll
    2012-07-22 02:12 . 2012-07-22 02:12 96768 ----a-w- c:\windows\system32\mshtmled.dll
    2012-07-22 01:58 . 2012-06-12 03:02 3147264 ----a-w- c:\windows\system32\win32k.sys
    2012-07-22 01:58 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
    2012-07-22 01:58 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
    2012-07-22 00:32 . 2012-07-22 00:32 -------- d-----w- c:\windows\SysWow64\Wat
    2012-07-22 00:32 . 2012-07-22 00:32 -------- d-----w- c:\windows\system32\Wat
    2012-07-22 00:20 . 2012-07-03 08:19 59701280 ----a-w- c:\windows\system32\MRT.exe
    2012-07-22 00:17 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
    2012-07-22 00:17 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
    2012-07-22 00:17 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
    2012-07-22 00:17 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
    2012-07-22 00:17 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
    2012-07-22 00:17 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
    2012-07-21 21:16 . 2008-07-31 15:41 68616 ----a-w- c:\windows\SysWow64\XAPOFX1_1.dll
    2012-07-21 21:16 . 2008-07-31 15:40 509448 ----a-w- c:\windows\SysWow64\XAudio2_2.dll
    2012-07-21 21:16 . 2008-07-12 13:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
    2012-07-21 21:16 . 2008-07-12 13:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
    2012-07-21 21:16 . 2008-07-12 13:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
    2012-07-21 21:13 . 2012-07-21 21:13 -------- d-----w- C:\Riot Games
    2012-07-21 20:54 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2012-07-21 20:54 . 2012-03-01 06:45 220672 ----a-w- c:\windows\system32\wintrust.dll
    2012-07-21 20:54 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
    2012-07-21 20:54 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
    2012-07-21 20:54 . 2012-03-01 05:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
    2012-07-21 20:54 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
    2012-07-21 20:54 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
    2012-07-21 20:52 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
    2012-07-21 20:51 . 2012-07-21 17:57 -------- d-----w- c:\windows\Panther
    2012-07-21 20:17 . 2011-10-26 05:22 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-07-21 20:16 . 2010-12-21 06:15 264192 ----a-w- c:\windows\system32\upnp.dll
    2012-07-21 20:09 . 2012-04-26 05:34 76288 ----a-w- c:\windows\system32\rdpwsx.dll
    2012-07-21 20:08 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
    2012-07-21 20:07 . 2011-02-05 12:41 556928 ----a-w- c:\windows\system32\winresume.efi
    2012-07-21 20:06 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-07-21 20:06 . 2012-04-02 05:26 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
    2012-07-21 20:06 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06 . 2012-04-02 05:24 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
    2012-07-21 20:06 . 2012-04-02 05:24 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
    2012-07-21 20:06 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
    2012-07-21 20:06 . 2012-06-06 05:09 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
    2012-07-21 20:06 . 2011-11-17 07:14 1739160 ----a-w- c:\windows\system32\ntdll.dll
    2012-07-21 20:06 . 2011-11-17 05:41 1292592 ----a-w- c:\windows\SysWow64\ntdll.dll
    2012-07-21 20:06 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
    2012-07-21 20:06 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
    2012-07-21 20:00 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
    2012-07-21 20:00 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
    2012-07-21 19:33 . 2012-07-22 05:12 -------- d-----w- c:\programdata\PMB Files
    2012-07-21 19:33 . 2012-07-21 19:43 -------- d-----w- c:\program files (x86)\Common Files\Steam
    2012-07-21 19:33 . 2012-07-22 23:01 -------- d-----w- c:\program files (x86)\Steam
    2012-07-21 19:33 . 2012-07-21 19:33 -------- d-----w- c:\program files (x86)\Pando Networks
    2012-07-21 18:48 . 2012-07-21 18:48 -------- d-----w- c:\programdata\Sophos
    2012-07-21 18:43 . 2012-07-21 18:43 0 ----a-w- c:\windows\ativpsrm.bin
    2012-07-21 18:41 . 2012-07-22 22:02 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-07-21 18:33 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
    2012-07-21 18:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
    2012-07-21 18:33 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
    2012-07-21 18:33 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
    2012-07-21 18:33 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
    2012-07-21 18:25 . 2012-07-21 18:25 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
    2012-07-21 18:21 . 2012-07-22 02:38 -------- d-----w- c:\program files\ATI Technologies
    2012-07-21 18:21 . 2012-07-21 18:21 -------- d-----w- c:\program files\ATI
    2012-07-21 18:21 . 2012-07-21 18:21 -------- d-----w- C:\AMD
    2012-07-21 18:20 . 2012-07-21 18:20 927800 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9A70AE52-D427-4C6E-A954-A32D38311C2F}\gapaengine.dll
    2012-07-21 18:20 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe
    2012-07-21 18:15 . 2012-07-21 18:15 -------- d-----w- c:\program files (x86)\Microsoft Security Client
    2012-07-21 18:15 . 2012-07-21 18:15 -------- d-----w- c:\program files\Microsoft Security Client
    2012-07-21 18:15 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
    2012-07-21 18:03 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-07-21 18:03 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-07-21 18:03 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-07-21 18:03 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-07-21 18:02 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
    2012-07-21 18:02 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
    2012-07-21 18:02 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
    2012-07-21 18:02 . 2012-06-02 20:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-07-21 18:02 . 2012-06-02 20:15 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-07-21 18:01 . 2012-07-21 21:13 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
    2012-07-21 18:01 . 2012-07-21 18:01 -------- d-----w- C:\OEMSettings
    2012-07-21 18:01 . 2009-11-18 22:47 446976 ----a-w- c:\windows\system32\drivers\wg111v3.sys
    2012-07-21 18:01 . 2012-07-21 18:01 -------- d-----w- c:\program files (x86)\NETGEAR
    2012-07-21 17:58 . 2012-07-22 21:25 -------- d-sh--w- c:\windows\Installer
    2012-07-21 17:58 . 2012-07-21 17:58 -------- d-----w- c:\windows\Downloaded Installations
    2012-07-21 17:57 . 2012-07-21 19:33 -------- d-----w- c:\users\Vincent
    2012-07-21 17:57 . 2012-07-21 17:57 -------- d-----w- C:\Recovery
    2012-07-04 07:30 . 2012-07-04 07:30 54784 ----a-w- c:\windows\system32\OpenCL.dll
    2012-07-04 07:30 . 2012-07-04 07:30 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe
    2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
    2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
    2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
    2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
    2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
    2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
    2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
    2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
    2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll
    2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
    2012-06-11 17:24 . 2012-06-11 17:24 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll
    2012-06-11 17:23 . 2011-01-27 03:59 1090560 ----a-w- c:\windows\system32\aticfx64.dll
    2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
    2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
    2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
    2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
    2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
    2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
    2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll
    2012-06-11 17:01 . 2011-01-27 03:40 6914560 ----a-w- c:\windows\system32\atidxx64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
    2012-06-11 16:45 . 2012-06-11 16:45 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll
    2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
    2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
    2012-06-11 16:43 . 2012-06-11 16:43 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll
    2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll
    2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
    2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2012-06-11 16:25 . 2012-06-11 16:25 54784 ----a-w- c:\windows\system32\atiuxp64.dll
    2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll
    2012-06-11 16:24 . 2012-06-11 16:24 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll
    2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-07-21 1242448]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HDDHealth.lnk - c:\program files (x86)\HDD Health\hddhealth.exe [2012-7-22 1987520]
    NETGEAR WG111v3 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WG111v3\WG111v3.exe [2009-11-6 2469888]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 HDDHealth;HDDHealth;c:\program files (x86)\HDD Health\HDDHealthService.exe [2012-06-07 72640]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
    R3 54556415;54556415;c:\windows\system32\drivers\18033299.sys [x]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 250056]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
    R3 SophosVirusRemovalTool;Sophos Virus Removal Tool;c:\program files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-22 1255736]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
    S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-21 98688]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
    S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
    S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2009-11-18 446976]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 08:29]
    .
    2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000Core.job
    - c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21 18:07]
    .
    2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000UA.job
    - c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21 18:07]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\dbiou9hx.default\
    FF - prefs.js: browser.startup.homepage - gmail.com
    .
    - - - - ORPHANS REMOVED - - - -
    .
    SafeBoot-54556415.sys
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-07-22 18:04:32 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-07-22 23:04
    .
    Pre-Run: 947,612,540,928 bytes free
    Post-Run: 947,683,794,944 bytes free
    .
    - - End Of File - - 9B4354BDA13F78886DB17917F8B35EE0
     
  21. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    1. Please open Notepad (Start>All Programs>Accessories>Notepad).

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\drivers\18033299.sys
    
    Driver::
    54556415
    
    ClearJavaCache::
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  22. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    New CF:
    ComboFix 12-07-21.01 - Vincent 07/22/2012 18:32:17.2.4 - x64
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.6142.4661 [GMT -5:00]
    Running from: c:\users\Vincent\Desktop\ComboFix.exe
    Command switches used :: c:\users\Vincent\Desktop\cfscript.txt
    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    FILE ::
    "c:\windows\system32\drivers\18033299.sys"
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_54556415
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
    .
    .
    2012-07-22 23:34 . 2012-07-22 23:34 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-07-22 23:05 . 2012-06-29 08:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B54D78D9-538F-482D-9386-0857C7AA068F}\mpengine.dll
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----r- c:\program files (x86)\Skype
    2012-07-22 08:40 . 2012-07-22 08:40 -------- d-----w- c:\programdata\Skype
    2012-07-22 08:37 . 2012-07-22 08:37 -------- d-----w- c:\program files (x86)\HDD Health
    2012-07-22 08:29 . 2012-07-22 08:29 -------- d-----w- c:\programdata\McAfee
    2012-07-22 08:29 . 2012-07-22 08:29 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-22 08:29 . 2012-07-22 08:29 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-07-22 08:28 . 2012-07-22 08:28 -------- d-----w- c:\windows\SysWow64\Macromed
    2012-07-22 08:28 . 2012-07-22 08:28 -------- d-----w- c:\windows\system32\Macromed
    2012-07-22 05:17 . 2012-07-22 05:17 -------- d-----w- c:\programdata\Malwarebytes
    2012-07-22 05:17 . 2012-07-22 05:17 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-07-22 05:17 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-22 04:18 . 2012-07-22 04:19 -------- d-----w- c:\program files\WinRAR
    2012-07-22 04:03 . 2008-03-05 20:56 4910088 ----a-w- c:\windows\system32\D3DX9_37.dll
    2012-07-22 02:39 . 2012-07-22 02:39 -------- d-----w- c:\programdata\ATI
    2012-07-22 02:39 . 2012-07-22 02:39 -------- d-----w- c:\program files (x86)\AMD APP
    2012-07-22 02:35 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
    2012-07-22 02:35 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
    2012-07-22 02:35 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\programdata\AMD
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\AMD AVT
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files\Common Files\ATI Technologies
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
    2012-07-22 02:32 . 2012-07-22 02:32 -------- d-----w- c:\program files (x86)\ATI Technologies
    2012-07-22 02:29 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
    2012-07-22 02:29 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
    2012-07-22 02:28 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2012-07-22 02:28 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
    2012-07-22 02:27 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll
    2012-07-22 02:26 . 2012-07-22 02:26 -------- d-----w- c:\program files (x86)\Microsoft.NET
    2012-07-22 02:26 . 2012-07-22 02:26 1831424 ----a-w- c:\windows\SysWow64\atiumdmv.dll
    2012-07-22 02:26 . 2012-07-22 02:26 1120768 ----a-w- c:\windows\system32\atiumd6v.dll
    2012-07-22 02:12 . 2012-07-22 02:12 96768 ----a-w- c:\windows\system32\mshtmled.dll
    2012-07-22 01:58 . 2012-06-12 03:02 3147264 ----a-w- c:\windows\system32\win32k.sys
    2012-07-22 01:58 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
    2012-07-22 01:58 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
    2012-07-22 00:32 . 2012-07-22 00:32 -------- d-----w- c:\windows\SysWow64\Wat
    2012-07-22 00:32 . 2012-07-22 00:32 -------- d-----w- c:\windows\system32\Wat
    2012-07-22 00:20 . 2012-07-03 08:19 59701280 ----a-w- c:\windows\system32\MRT.exe
    2012-07-22 00:17 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
    2012-07-22 00:17 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
    2012-07-22 00:17 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
    2012-07-22 00:17 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
    2012-07-22 00:17 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
    2012-07-22 00:17 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
    2012-07-22 00:17 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
    2012-07-21 21:16 . 2008-07-31 15:41 68616 ----a-w- c:\windows\SysWow64\XAPOFX1_1.dll
    2012-07-21 21:16 . 2008-07-31 15:40 509448 ----a-w- c:\windows\SysWow64\XAudio2_2.dll
    2012-07-21 21:16 . 2008-07-12 13:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
    2012-07-21 21:16 . 2008-07-12 13:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
    2012-07-21 21:16 . 2008-07-12 13:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
    2012-07-21 21:13 . 2012-07-21 21:13 -------- d-----w- C:\Riot Games
    2012-07-21 20:54 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2012-07-21 20:54 . 2012-03-01 06:45 220672 ----a-w- c:\windows\system32\wintrust.dll
    2012-07-21 20:54 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
    2012-07-21 20:54 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
    2012-07-21 20:54 . 2012-03-01 05:49 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
    2012-07-21 20:54 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
    2012-07-21 20:54 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
    2012-07-21 20:52 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
    2012-07-21 20:51 . 2012-07-21 17:57 -------- d-----w- c:\windows\Panther
    2012-07-21 20:17 . 2011-10-26 05:22 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-07-21 20:16 . 2010-12-21 06:15 264192 ----a-w- c:\windows\system32\upnp.dll
    2012-07-21 20:09 . 2012-04-26 05:34 76288 ----a-w- c:\windows\system32\rdpwsx.dll
    2012-07-21 20:08 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
    2012-07-21 20:07 . 2011-02-05 12:41 556928 ----a-w- c:\windows\system32\winresume.efi
    2012-07-21 20:06 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-07-21 20:06 . 2012-04-02 05:26 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
    2012-07-21 20:06 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06 . 2012-04-02 05:24 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
    2012-07-21 20:06 . 2012-04-02 05:24 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
    2012-07-21 20:06 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-07-21 20:06 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
    2012-07-21 20:06 . 2012-06-06 05:09 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
    2012-07-21 20:06 . 2011-11-17 07:14 1739160 ----a-w- c:\windows\system32\ntdll.dll
    2012-07-21 20:06 . 2011-11-17 05:41 1292592 ----a-w- c:\windows\SysWow64\ntdll.dll
    2012-07-21 20:06 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
    2012-07-21 20:06 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
    2012-07-21 20:00 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
    2012-07-21 20:00 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
    2012-07-21 19:33 . 2012-07-22 05:12 -------- d-----w- c:\programdata\PMB Files
    2012-07-21 19:33 . 2012-07-21 19:43 -------- d-----w- c:\program files (x86)\Common Files\Steam
    2012-07-21 19:33 . 2012-07-22 23:36 -------- d-----w- c:\program files (x86)\Steam
    2012-07-21 19:33 . 2012-07-21 19:33 -------- d-----w- c:\program files (x86)\Pando Networks
    2012-07-21 18:48 . 2012-07-21 18:48 -------- d-----w- c:\programdata\Sophos
    2012-07-21 18:43 . 2012-07-21 18:43 0 ----a-w- c:\windows\ativpsrm.bin
    2012-07-21 18:41 . 2012-07-22 22:02 -------- d-----w- C:\TDSSKiller_Quarantine
    2012-07-21 18:33 . 2010-01-09 07:19 139264 ----a-w- c:\windows\system32\cabview.dll
    2012-07-21 18:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\SysWow64\cabview.dll
    2012-07-21 18:33 . 2012-02-15 06:27 1031680 ----a-w- c:\windows\system32\rdpcore.dll
    2012-07-21 18:33 . 2012-02-15 05:44 826368 ----a-w- c:\windows\SysWow64\rdpcore.dll
    2012-07-21 18:33 . 2012-02-15 04:46 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
    2012-07-21 18:25 . 2012-07-21 18:25 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
    2012-07-21 18:21 . 2012-07-22 02:38 -------- d-----w- c:\program files\ATI Technologies
    2012-07-21 18:21 . 2012-07-21 18:21 -------- d-----w- c:\program files\ATI
    2012-07-21 18:21 . 2012-07-21 18:21 -------- d-----w- C:\AMD
    2012-07-21 18:20 . 2012-07-21 18:20 927800 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9A70AE52-D427-4C6E-A954-A32D38311C2F}\gapaengine.dll
    2012-07-21 18:20 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe
    2012-07-21 18:15 . 2012-07-21 18:15 -------- d-----w- c:\program files (x86)\Microsoft Security Client
    2012-07-21 18:15 . 2012-07-21 18:15 -------- d-----w- c:\program files\Microsoft Security Client
    2012-07-21 18:15 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
    2012-07-21 18:03 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
    2012-07-21 18:03 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
    2012-07-21 18:03 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
    2012-07-21 18:03 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
    2012-07-21 18:02 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
    2012-07-21 18:02 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
    2012-07-21 18:02 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
    2012-07-21 18:02 . 2012-06-02 20:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
    2012-07-21 18:02 . 2012-06-02 20:15 36864 ----a-w- c:\windows\system32\wuapp.exe
    2012-07-21 18:01 . 2012-07-21 21:13 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
    2012-07-21 18:01 . 2012-07-21 18:01 -------- d-----w- C:\OEMSettings
    2012-07-21 18:01 . 2009-11-18 22:47 446976 ----a-w- c:\windows\system32\drivers\wg111v3.sys
    2012-07-21 18:01 . 2012-07-21 18:01 -------- d-----w- c:\program files (x86)\NETGEAR
    2012-07-21 17:58 . 2012-07-22 21:25 -------- d-sh--w- c:\windows\Installer
    2012-07-21 17:58 . 2012-07-21 17:58 -------- d-----w- c:\windows\Downloaded Installations
    2012-07-21 17:57 . 2012-07-21 19:33 -------- d-----w- c:\users\Vincent
    2012-07-21 17:57 . 2012-07-21 17:57 -------- d-----w- C:\Recovery
    2012-07-04 07:30 . 2012-07-04 07:30 54784 ----a-w- c:\windows\system32\OpenCL.dll
    2012-07-04 07:30 . 2012-07-04 07:30 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe
    2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
    2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
    2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
    2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
    2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
    2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
    2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
    2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
    2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll
    2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
    2012-06-11 17:24 . 2012-06-11 17:24 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll
    2012-06-11 17:23 . 2011-01-27 03:59 1090560 ----a-w- c:\windows\system32\aticfx64.dll
    2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
    2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
    2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
    2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
    2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
    2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
    2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll
    2012-06-11 17:01 . 2011-01-27 03:40 6914560 ----a-w- c:\windows\system32\atidxx64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
    2012-06-11 16:45 . 2012-06-11 16:45 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll
    2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
    2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
    2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
    2012-06-11 16:43 . 2012-06-11 16:43 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll
    2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll
    2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
    2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
    2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2012-06-11 16:25 . 2012-06-11 16:25 54784 ----a-w- c:\windows\system32\atiuxp64.dll
    2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll
    2012-06-11 16:24 . 2012-06-11 16:24 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll
    2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
    2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-07-22_23.01.52 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2012-07-21 18:20 . 2012-07-22 23:03 22970 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2012-07-22 23:03 29364 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 04:46 . 2012-07-22 23:35 76848 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    + 2012-07-21 18:08 . 2012-07-22 23:03 5646 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1667560427-3386010797-3322070579-1000_UserData.bin
    + 2012-07-22 23:35 . 2012-07-22 23:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2012-07-22 23:01 . 2012-07-22 23:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2012-07-22 23:01 . 2012-07-22 23:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2012-07-22 23:35 . 2012-07-22 23:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2009-07-14 05:01 . 2012-07-22 23:00 229236 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2009-07-14 05:01 . 2012-07-22 23:35 229236 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2012-07-21 18:42 . 2012-07-22 23:35 2393708 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1667560427-3386010797-3322070579-1000-8192.dat
    - 2009-07-14 02:34 . 2012-07-22 22:17 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
    + 2009-07-14 02:34 . 2012-07-22 23:14 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-07-21 1242448]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HDDHealth.lnk - c:\program files (x86)\HDD Health\hddhealth.exe [2012-7-22 1987520]
    NETGEAR WG111v3 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WG111v3\WG111v3.exe [2009-11-6 2469888]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 HDDHealth;HDDHealth;c:\program files (x86)\HDD Health\HDDHealthService.exe [2012-06-07 72640]
    R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 250056]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
    R3 SophosVirusRemovalTool;Sophos Virus Removal Tool;c:\program files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-22 1255736]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
    S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-21 98688]
    S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
    S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
    S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2009-11-18 446976]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 08:29]
    .
    2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000Core.job
    - c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21 18:07]
    .
    2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000UA.job
    - c:\users\Vincent\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-21 18:07]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
    "combofix"="c:\combofix\CF3469.3XE" [2009-07-14 344576]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\dbiou9hx.default\
    FF - prefs.js: browser.startup.homepage - gmail.com
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-07-22 18:38:30 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-07-22 23:38
    ComboFix2.txt 2012-07-22 23:04
    .
    Pre-Run: 947,740,708,864 bytes free
    Post-Run: 947,568,447,488 bytes free
    .
    - - End Of File - - EE9EB317812A8E2E5660F665116DC727
     
  23. Broni

    Broni Malware Annihilator Posts: 52,904   +344

    Looks good.

    How is computer doing?

    ===============================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  24. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    OTL:
    OTL logfile created on: 7/22/2012 8:35:31 PM - Run 2
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Vincent\Desktop
    64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    6.00 Gb Total Physical Memory | 4.50 Gb Available Physical Memory | 75.08% Memory free
    12.00 Gb Paging File | 10.57 Gb Available in Paging File | 88.15% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 931.41 Gb Total Space | 882.56 Gb Free Space | 94.76% Space Free | Partition Type: NTFS
    Drive D: | 698.63 Gb Total Space | 390.65 Gb Free Space | 55.92% Space Free | Partition Type: NTFS
    Drive E: | 100.00 Mb Total Space | 60.77 Mb Free Space | 60.77% Space Free | Partition Type: NTFS
    Drive F: | 931.41 Gb Total Space | 194.55 Gb Free Space | 20.89% Space Free | Partition Type: NTFS
    Drive H: | 7.46 Gb Total Space | 5.43 Gb Free Space | 72.83% Space Free | Partition Type: NTFS

    Computer Name: NOISEMACHINE | User Name: Vincent | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/07/22 20:32:17 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
    PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/06/07 09:17:26 | 001,987,520 | ---- | M] (PANTERASoft) -- C:\Program Files (x86)\HDD Health\hddhealth.exe
    PRC - [2009/11/06 14:36:32 | 002,469,888 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe


    ========== Modules (No Company Name) ==========

    MOD - [2009/11/06 14:36:32 | 002,469,888 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WG111v3\WG111v3.exe
    MOD - [2009/03/04 09:52:36 | 000,372,736 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WG111v3\WlanDll.dll
    MOD - [2008/12/29 17:13:24 | 000,204,800 | ---- | M] () -- C:\Program Files (x86)\NETGEAR\WG111v3\KJLog.dll


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2012/06/11 12:19:14 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
    SRV - [2012/07/22 03:29:05 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/21 14:35:55 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2012/07/13 19:17:12 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/06/07 09:17:28 | 000,072,640 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\HDD Health\HDDHealthService.exe -- (HDDHealth)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/06/11 13:59:38 | 010,248,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2012/06/11 11:26:14 | 000,367,616 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV:64bit: - [2012/03/01 01:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/23 07:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
    DRV:64bit: - [2009/11/18 17:47:46 | 000,446,976 | ---- | M] (NETGEAR Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wg111v3.sys -- (RTL8187B)
    DRV:64bit: - [2009/07/13 20:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2009/07/13 20:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/06/10 15:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 11 1C D8 FD 6A 67 CD 01 [binary data]
    IE - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "gmail.com"
    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/21 13:24:59 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

    [2012/07/21 13:25:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\Mozilla\Extensions
    [2012/07/21 14:30:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Vincent\AppData\Roaming\Mozilla\Firefox\Profiles\dbiou9hx.default\extensions
    [2012/07/21 13:24:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2012/07/21 14:30:37 | 000,001,229 | ---- | M] () (No name found) -- C:\USERS\VINCENT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DBIOU9HX.DEFAULT\EXTENSIONS\{7EDCDFC0-3056-11E0-91FA-0800200C9A66}.XPI
    [2012/07/13 19:17:47 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2012/07/13 19:16:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/07/13 19:16:36 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Vincent\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
    CHR - plugin: Google Update (Enabled) = C:\Users\Vincent\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - Extension: YouTube = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: Gmail = C:\Users\Vincent\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2012/07/22 18:36:03 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1667560427-3386010797-3322070579-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F0F8016D-0890-4031-B355-CC1A7C559357}: DhcpNameServer = 192.168.1.254
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18 - Protocol\Handler\gopher - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/07/22 20:32:11 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
    [2012/07/22 18:38:32 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2012/07/22 18:31:37 | 000,000,000 | ---D | C] -- C:\ComboFix
    [2012/07/22 17:57:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/07/22 17:57:15 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/07/22 17:57:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/07/22 17:57:12 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/07/22 17:57:03 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/07/22 17:53:23 | 004,582,474 | R--- | C] (Swearware) -- C:\Users\Vincent\Desktop\ComboFix.exe
    [2012/07/22 16:14:50 | 000,000,000 | ---D | C] -- C:\Config.Msi
    [2012/07/22 15:00:32 | 002,136,664 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Vincent\Desktop\tdsskiller.exe
    [2012/07/22 14:17:55 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\RK_Quarantine
    [2012/07/22 14:16:43 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Vincent\Desktop\aswMBR.exe
    [2012/07/22 03:40:33 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Skype
    [2012/07/22 03:40:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    [2012/07/22 03:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
    [2012/07/22 03:40:25 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
    [2012/07/22 03:40:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
    [2012/07/22 03:37:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Health
    [2012/07/22 03:37:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HDD Health
    [2012/07/22 03:33:15 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Macromedia
    [2012/07/22 03:29:30 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
    [2012/07/22 03:28:59 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
    [2012/07/22 03:28:57 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
    [2012/07/22 03:00:14 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\Sheet Music
    [2012/07/22 03:00:00 | 000,000,000 | ---D | C] -- C:\Users\Vincent\Desktop\The Embodiment of Scarlet Devil
    [2012/07/22 00:17:56 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Malwarebytes
    [2012/07/22 00:17:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/07/22 00:17:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/07/22 00:17:46 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/07/22 00:17:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/07/21 23:19:46 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\WinRAR
    [2012/07/21 23:19:46 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2012/07/21 23:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2012/07/21 23:18:57 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2012/07/21 22:59:23 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
    [2012/07/21 21:39:34 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\LolClient
    [2012/07/21 21:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
    [2012/07/21 21:39:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
    [2012/07/21 21:38:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
    [2012/07/21 21:32:24 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\ATI
    [2012/07/21 21:32:24 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\ATI
    [2012/07/21 21:32:24 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
    [2012/07/21 21:32:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
    [2012/07/21 21:32:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
    [2012/07/21 21:32:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
    [2012/07/21 21:32:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
    [2012/07/21 21:26:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
    [2012/07/21 20:48:41 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Diagnostics
    [2012/07/21 19:32:31 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
    [2012/07/21 19:32:31 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
    [2012/07/21 16:13:17 | 000,000,000 | ---D | C] -- C:\Riot Games
    [2012/07/21 16:13:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
    [2012/07/21 15:51:20 | 000,000,000 | ---D | C] -- C:\Windows\Panther
    [2012/07/21 14:52:33 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
    [2012/07/21 14:52:08 | 000,000,000 | -HSD | C] -- C:\System Volume Information
    [2012/07/21 14:33:51 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\PMB Files
    [2012/07/21 14:33:50 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
    [2012/07/21 14:33:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    [2012/07/21 14:33:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
    [2012/07/21 14:33:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
    [2012/07/21 14:33:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
    [2012/07/21 13:48:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
    [2012/07/21 13:41:23 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
    [2012/07/21 13:28:14 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2012/07/21 13:25:12 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Mozilla
    [2012/07/21 13:25:12 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Mozilla
    [2012/07/21 13:25:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
    [2012/07/21 13:25:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
    [2012/07/21 13:24:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
    [2012/07/21 13:21:30 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
    [2012/07/21 13:21:29 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
    [2012/07/21 13:21:00 | 000,000,000 | ---D | C] -- C:\AMD
    [2012/07/21 13:15:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
    [2012/07/21 13:15:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/07/21 13:08:53 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Macromedia
    [2012/07/21 13:08:53 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Adobe
    [2012/07/21 13:08:21 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2012/07/21 13:07:15 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Google
    [2012/07/21 13:03:16 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Deployment
    [2012/07/21 13:03:16 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Apps
    [2012/07/21 13:01:31 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
    [2012/07/21 13:01:31 | 000,000,000 | ---D | C] -- C:\OEMSettings
    [2012/07/21 13:01:12 | 000,446,976 | ---- | C] (NETGEAR Inc. ) -- C:\Windows\SysNative\drivers\wg111v3.sys
    [2012/07/21 13:01:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NETGEAR
    [2012/07/21 13:01:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WG111v3 Smart Wizard
    [2012/07/21 13:00:19 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\ElevatedDiagnostics
    [2012/07/21 12:58:52 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
    [2012/07/21 12:58:52 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
    [2012/07/21 12:58:05 | 000,000,000 | R--D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    [2012/07/21 12:58:05 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Searches
    [2012/07/21 12:58:05 | 000,000,000 | R--D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    [2012/07/21 12:58:05 | 000,000,000 | -H-D | C] -- C:\Users\Vincent\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
    [2012/07/21 12:57:58 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Identities
    [2012/07/21 12:57:57 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Contacts
    [2012/07/21 12:57:55 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\VirtualStore
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\AppData\Local\Temporary Internet Files
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Templates
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Start Menu
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\SendTo
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Recent
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\PrintHood
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\NetHood
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Documents\My Videos
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Documents\My Pictures
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Documents\My Music
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\My Documents
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Local Settings
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\AppData\Local\History
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Cookies
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\Application Data
    [2012/07/21 12:57:50 | 000,000,000 | -HSD | C] -- C:\Users\Vincent\AppData\Local\Application Data
    [2012/07/21 12:57:49 | 000,000,000 | --SD | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Videos
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Saved Games
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Pictures
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Music
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Links
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Favorites
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Downloads
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Documents
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\Desktop
    [2012/07/21 12:57:49 | 000,000,000 | R--D | C] -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    [2012/07/21 12:57:49 | 000,000,000 | -H-D | C] -- C:\Users\Vincent\AppData
    [2012/07/21 12:57:49 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Temp
    [2012/07/21 12:57:49 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Local\Microsoft
    [2012/07/21 12:57:49 | 000,000,000 | ---D | C] -- C:\Users\Vincent\AppData\Roaming\Media Center Programs
    [2012/07/21 12:57:43 | 000,000,000 | ---D | C] -- C:\Recovery
    [2012/07/21 12:57:42 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
    [2012/07/04 02:30:12 | 000,054,784 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
    [2012/07/04 02:30:08 | 000,050,176 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/07/22 20:32:17 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Vincent\Desktop\OTL.exe
    [2012/07/22 20:17:00 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000UA.job
    [2012/07/22 20:08:03 | 000,012,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/07/22 20:08:03 | 000,012,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/07/22 19:47:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/07/22 18:36:03 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/07/22 18:35:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/07/22 18:35:47 | 535,683,071 | -HS- | M] () -- C:\hiberfil.sys
    [2012/07/22 17:54:09 | 004,582,474 | R--- | M] (Swearware) -- C:\Users\Vincent\Desktop\ComboFix.exe
    [2012/07/22 16:24:45 | 000,743,278 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/07/22 16:24:45 | 000,626,040 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/07/22 16:24:45 | 000,107,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/07/22 14:17:11 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Vincent\Desktop\aswMBR.exe
    [2012/07/22 14:16:36 | 001,552,384 | ---- | M] () -- C:\Users\Vincent\Desktop\RogueKiller.exe
    [2012/07/22 13:17:02 | 000,000,864 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000Core.job
    [2012/07/22 12:56:04 | 693,820,514 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2012/07/22 03:40:28 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2012/07/22 03:37:02 | 000,001,048 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDDHealth.lnk
    [2012/07/22 00:17:50 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/21 21:29:59 | 000,157,144 | ---- | M] () -- C:\Windows\SysWow64\ativvsva.dat
    [2012/07/21 21:29:59 | 000,157,144 | ---- | M] () -- C:\Windows\SysNative\ativvsva.dat
    [2012/07/21 21:29:32 | 000,204,952 | ---- | M] () -- C:\Windows\SysWow64\ativvsvl.dat
    [2012/07/21 21:29:32 | 000,204,952 | ---- | M] () -- C:\Windows\SysNative\ativvsvl.dat
    [2012/07/21 21:28:33 | 000,003,917 | ---- | M] () -- C:\Windows\SysWow64\atipblag.dat
    [2012/07/21 21:28:33 | 000,003,917 | ---- | M] () -- C:\Windows\SysNative\atipblag.dat
    [2012/07/21 21:24:19 | 000,001,441 | ---- | M] () -- C:\Users\Vincent\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2012/07/21 21:23:31 | 000,274,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/07/21 21:13:01 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
    [2012/07/21 21:12:59 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
    [2012/07/21 16:16:55 | 000,001,720 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2012/07/21 14:55:03 | 000,042,045 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
    [2012/07/21 14:55:03 | 000,042,045 | ---- | M] () -- C:\Windows\SysNative\license.rtf
    [2012/07/21 14:33:30 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
    [2012/07/21 13:43:22 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
    [2012/07/21 13:39:50 | 002,136,664 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Vincent\Desktop\tdsskiller.exe
    [2012/07/21 13:25:07 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2012/07/21 13:17:54 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/07/21 13:15:52 | 000,730,638 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/07/21 13:08:22 | 000,002,288 | ---- | M] () -- C:\Users\Vincent\Desktop\Google Chrome.lnk
    [2012/07/21 13:01:12 | 000,002,073 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
    [2012/07/21 13:01:12 | 000,002,051 | ---- | M] () -- C:\Users\Public\Desktop\NETGEAR WG111v3 Smart Wizard.lnk
    [2012/07/21 12:58:34 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
    [2012/07/04 02:30:12 | 000,054,784 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
    [2012/07/04 02:30:08 | 000,050,176 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
    [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/07/22 17:57:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/07/22 17:57:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/07/22 17:57:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/07/22 17:57:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/07/22 17:57:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/07/22 14:16:14 | 001,552,384 | ---- | C] () -- C:\Users\Vincent\Desktop\RogueKiller.exe
    [2012/07/22 03:40:28 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
    [2012/07/22 03:37:02 | 000,001,048 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDDHealth.lnk
    [2012/07/22 03:29:08 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/07/22 00:17:50 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/07/21 21:29:58 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
    [2012/07/21 21:29:58 | 000,157,144 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
    [2012/07/21 21:29:28 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
    [2012/07/21 21:29:28 | 000,204,952 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
    [2012/07/21 21:28:33 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2012/07/21 21:28:33 | 000,003,917 | ---- | C] () -- C:\Windows\SysNative\atipblag.dat
    [2012/07/21 21:13:01 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
    [2012/07/21 21:12:59 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
    [2012/07/21 16:16:55 | 000,001,720 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2012/07/21 14:54:46 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
    [2012/07/21 14:54:40 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
    [2012/07/21 14:52:08 | 535,683,071 | -HS- | C] () -- C:\hiberfil.sys
    [2012/07/21 14:33:30 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
    [2012/07/21 13:43:22 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2012/07/21 13:28:10 | 693,820,514 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2012/07/21 13:25:07 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
    [2012/07/21 13:25:06 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    [2012/07/21 13:17:54 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
    [2012/07/21 13:15:55 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/07/21 13:15:52 | 000,730,638 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2012/07/21 13:08:22 | 000,002,288 | ---- | C] () -- C:\Users\Vincent\Desktop\Google Chrome.lnk
    [2012/07/21 13:07:16 | 000,000,916 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000UA.job
    [2012/07/21 13:07:15 | 000,000,864 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1667560427-3386010797-3322070579-1000Core.job
    [2012/07/21 13:02:24 | 000,001,441 | ---- | C] () -- C:\Users\Vincent\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2012/07/21 13:01:12 | 000,002,073 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
    [2012/07/21 13:01:12 | 000,002,051 | ---- | C] () -- C:\Users\Public\Desktop\NETGEAR WG111v3 Smart Wizard.lnk
    [2012/07/21 12:58:34 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
    [2012/07/21 12:58:09 | 000,001,413 | ---- | C] () -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
    [2012/07/21 12:58:06 | 000,001,447 | ---- | C] () -- C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    [2012/07/21 12:57:49 | 000,000,290 | ---- | C] () -- C:\Users\Vincent\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
    [2012/07/21 12:57:49 | 000,000,272 | ---- | C] () -- C:\Users\Vincent\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
    [2012/03/09 14:06:14 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

    ========== LOP Check ==========

    [2012/07/21 21:39:34 | 000,000,000 | ---D | M] -- C:\Users\Vincent\AppData\Roaming\LolClient
    [2012/07/21 20:44:26 | 000,008,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    < End of report >
     
  25. Auvic

    Auvic TS Enthusiast Topic Starter Posts: 132

    Extras:
    OTL Extras logfile created on: 7/22/2012 8:32:52 PM - Run 1
    OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Vincent\Downloads
    64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    6.00 Gb Total Physical Memory | 4.59 Gb Available Physical Memory | 76.45% Memory free
    12.00 Gb Paging File | 10.60 Gb Available in Paging File | 88.38% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 931.41 Gb Total Space | 882.57 Gb Free Space | 94.76% Space Free | Partition Type: NTFS
    Drive D: | 698.63 Gb Total Space | 390.65 Gb Free Space | 55.92% Space Free | Partition Type: NTFS
    Drive E: | 100.00 Mb Total Space | 60.77 Mb Free Space | 60.77% Space Free | Partition Type: NTFS
    Drive F: | 931.41 Gb Total Space | 194.55 Gb Free Space | 20.89% Space Free | Partition Type: NTFS
    Drive H: | 7.46 Gb Total Space | 5.43 Gb Free Space | 72.83% Space Free | Partition Type: NTFS

    Computer Name: NOISEMACHINE | User Name: Vincent | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0704B56D-A4BF-43E0-ACA1-05A768DACBDB}" = lport=57639 | protocol=6 | dir=in | name=pando media booster |
    "{6FD90895-54FB-4BE1-8EED-BAD08AAEE821}" = lport=57639 | protocol=17 | dir=in | name=pando media booster |
    "{DDEFD7C3-2AFA-4998-99C8-B9AE494B9437}" = lport=57639 | protocol=6 | dir=in | name=pando media booster |
    "{F3A5FBF4-EA51-4850-B897-4EE47B8E2440}" = lport=57639 | protocol=17 | dir=in | name=pando media booster |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{101ABE37-AA06-469A-B2AB-FFE7FD4CA142}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "{50A5F474-3F78-4E68-BC17-C517B8C13853}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{603666FE-C19F-4E79-AC0A-EF06FCE557F9}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{638D702E-A2FD-4A82-A95E-5426B74ABB2F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{72A5D308-4998-4D7B-8851-F3247BDE85EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "{9729AD3A-5961-410A-9A4E-5C860D0EAA03}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "{BE2A9902-CE7E-46DC-817D-E5A445E4E3E5}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{C2A82C1C-23E5-4A74-AAD9-AB1E0264EDF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
    "{E790FEAE-20BC-46B0-B490-C5CCE954AEA9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |
    "{E9D2EB73-6C99-4285-8A13-C86117978550}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{47F9B7C3-F172-940F-D0C4-203C7914E5D2}" = AMD Catalyst Install Manager
    "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
    "{59B69525-1383-C84A-38EF-F442B63E69BC}" = AMD Media Foundation Decoders
    "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
    "{A71060CF-81D0-EC17-2252-78CA0E96CCCF}" = AMD Drag and Drop Transcoding
    "{BABA4667-CF82-B330-A8E5-6E8A09B2D911}" = AMD Accelerated Video Transcoding
    "{C8388DCB-6F85-C11F-C9F4-D636960E60F5}" = ccc-utility64
    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft Security Client" = Microsoft Security Essentials
    "WinRAR archiver" = WinRAR 4.20 (64-bit)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{079A4EB2-9A74-7B86-12C2-00B52E395801}" = CCC Help Danish
    "{112DDD07-E419-2498-1E9E-2157F82AF5AA}" = CCC Help Turkish
    "{12A00DC2-1226-D9F2-13DA-F974111D439E}" = Catalyst Control Center
    "{224828D6-DCA7-FDF3-3B85-085298AEC919}" = Catalyst Control Center InstallProxy
    "{2993B157-97AE-7981-F29A-E6575F991CDB}" = CCC Help Swedish
    "{347966F8-E71A-E1A5-95E4-3A1C215383F6}" = CCC Help Chinese Traditional
    "{3B3D81AB-51E2-695F-7E57-1CC30049F2A3}" = CCC Help French
    "{462C2036-3055-4369-D30B-8DA032331EAB}" = CCC Help Greek
    "{51054867-140B-8FBF-73A8-75386276BD98}" = CCC Help Spanish
    "{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
    "{586A5957-F21B-C8AD-F5C2-11D4D7DA5340}" = CCC Help German
    "{633414E3-AA2A-CD04-5976-E91F5F871396}" = CCC Help Japanese
    "{812FF572-F216-EBA0-123E-636C1B6EBC5B}" = CCC Help Korean
    "{85BB7CA7-6B0D-0B27-F4FF-B3D04282B3D1}" = CCC Help Russian
    "{883CCFC7-CA6B-5531-704B-F9A64546B309}" = CCC Help Thai
    "{8BDD3EC9-27E9-E490-7607-AF97FA678046}" = CCC Help Italian
    "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
    "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
    "{9DA5221E-15DE-5B0F-D7BE-CCC7305575DD}" = CCC Help Dutch
    "{A1400F57-65CC-0C22-6461-948EA2837670}" = CCC Help Hungarian
    "{A561BB5F-5A85-5D88-E520-0A4512D5E6C0}" = CCC Help Norwegian
    "{A8B72907-B3F5-4C18-2D2B-F5E786A520DF}" = CCC Help Polish
    "{AD219F94-16F2-937F-076A-F22DAA8D0A0B}" = CCC Help Finnish
    "{B2B5B39B-4E8C-AC78-7FF1-7055C338D243}" = Catalyst Control Center Graphics Previews Common
    "{DD8ACFF8-098E-130C-2799-BCA4D41EBAB2}" = CCC Help Chinese Standard
    "{DE123FE9-B7F6-A75A-920D-3937FB9F06E4}" = CCC Help Portuguese
    "{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
    "{EE253E80-C298-4A31-BB22-7280DC8C7177}" = CCC Help Czech
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
    "{F648F088-B270-CF18-6486-AF8B1FE6BC09}" = CCC Help English
    "{FD85D9C0-783A-77B7-8EF8-326EC6C154D1}" = Catalyst Control Center Localization All
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "HDD Health_is1" = HDD Health v4.2
    "InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
    "Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 7/22/2012 1:18:17 AM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: mbam.exe, version: 1.62.0.87, time stamp:
    0x4fc6d5ba Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x000339fe Faulting process id:
    0x35c Faulting application start time: 0x01cd67c95d1e54b5 Faulting application path:
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe Faulting module path:
    C:\Windows\SysWOW64\ntdll.dll Report Id: a4407291-d3bc-11e1-a085-00241ddde4fb

    Error - 7/22/2012 2:36:48 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: Skype.exe, version: 5.10.0.116, time stamp:
    0x50001496 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception
    code: 0xc0000005 Fault offset: 0x00000200 Faulting process id: 0xb28 Faulting application
    start time: 0x01cd6833574f5fa9 Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
    Faulting
    module path: unknown Report Id: 316927b9-d42c-11e1-a0b0-00241ddde4fb

    Error - 7/22/2012 3:07:20 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385,
    time stamp: 0x4a5bc3c1 Faulting module name: sysmain.dll, version: 6.1.7600.16385,
    time stamp: 0x4a5be07e Exception code: 0xc0000005 Fault offset: 0x000000000003f580
    Faulting
    process id: 0x3fc Faulting application start time: 0x01cd68334bc5ffe2 Faulting application
    path: C:\Windows\System32\svchost.exe Faulting module path: c:\windows\system32\sysmain.dll
    Report
    Id: 7576d3d6-d430-11e1-a0b0-00241ddde4fb

    Error - 7/22/2012 3:24:46 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e423 Faulting process id:
    0xc54 Faulting application start time: 0x01cd683ec5a53113 Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: e540ea4a-d432-11e1-998d-00241ddde4fb

    Error - 7/22/2012 3:33:20 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e423 Faulting process id:
    0xf60 Faulting application start time: 0x01cd684044643df6 Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: 17848db8-d434-11e1-998d-00241ddde4fb

    Error - 7/22/2012 3:40:23 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e3c6 Faulting process id:
    0x51c Faulting application start time: 0x01cd68415eb2745c Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: 1389e2f4-d435-11e1-9f3f-d0b470bd5799

    Error - 7/22/2012 3:54:01 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: Skype.exe, version: 5.10.0.116, time stamp:
    0x50001496 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
    Exception
    code: 0xc0000005 Fault offset: 0x00000200 Faulting process id: 0xac0 Faulting application
    start time: 0x01cd684385478bef Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
    Faulting
    module path: unknown Report Id: fb57bf74-d436-11e1-99ac-00241ddde4fb

    Error - 7/22/2012 4:37:55 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e423 Faulting process id:
    0x6f4 Faulting application start time: 0x01cd68493501df8a Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: 1d405ab2-d43d-11e1-99ac-00241ddde4fb

    Error - 7/22/2012 6:25:06 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e3c6 Faulting process id:
    0x7dc Faulting application start time: 0x01cd685838e97199 Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: 1694ebab-d44c-11e1-99a6-00241ddde4fb

    Error - 7/22/2012 6:50:00 PM | Computer Name = Noisemachine | Source = Application Error | ID = 1000
    Description = Faulting application name: aswMBR.exe, version: 0.9.9.1665, time stamp:
    0x4f5f9c86 Faulting module name: ntdll.dll, version: 6.1.7600.16915, time stamp:
    0x4ec49d10 Exception code: 0xc0000005 Fault offset: 0x0002e423 Faulting process id:
    0xf0c Faulting application start time: 0x01cd685b7c1555b2 Faulting application path:
    C:\Users\Vincent\Desktop\aswMBR.exe Faulting module path: C:\Windows\SysWOW64\ntdll.dll
    Report
    Id: 90dc7224-d44f-11e1-99a6-00241ddde4fb

    [ System Events ]
    Error - 7/22/2012 6:03:59 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the HDDHealth
    service to connect.

    Error - 7/22/2012 6:59:17 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 7/22/2012 7:00:47 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 7/22/2012 7:01:39 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the HDDHealth
    service to connect.

    Error - 7/22/2012 7:01:39 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126

    Error - 7/22/2012 7:33:26 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 7/22/2012 7:34:54 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 7/22/2012 7:34:57 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7030
    Description = The PEVSystemStart service is marked as an interactive service. However,
    the system is configured to not allow interactive services. This service may not
    function properly.

    Error - 7/22/2012 7:35:55 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the HDDHealth
    service to connect.

    Error - 7/22/2012 7:35:56 PM | Computer Name = Noisemachine | Source = Service Control Manager | ID = 7023
    Description = The Windows Defender service terminated with the following error:
    %%126


    < End of report >
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...